
PoisonApple
CLI tool for applying and removing macOS persistence mechanisms, designed for threat emulation and red team operations. Supports 17 techniques…

CLI tool for applying and removing macOS persistence mechanisms, designed for threat emulation and red team operations. Supports 17 techniques…

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

Reliable remote code execution exploit for CVE-2026-25243 targeting jemalloc Redis. Executes arbitrary commands via a single crafted RESTORE command…

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow leading to unauthenticated remote code execution via cron job…

Proof-of-concept exploit for a command injection vulnerability in VitalPBX Task Manager module, demonstrating reverse shell payload delivery via cron…

Python exploit toolkit for WordPress Crop Image RCE — CVE-2019-8942 & CVE-2019-8943

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's Scheduled Cron Jobs feature

Proof-of-concept exploit for CVE-2022-39952 targeting Fortinet FortiNAC. Abuses keyUpload.jsp endpoint for arbitrary file write to deploy cron-based…

Python Script that will DoS a WP server that is utilizing WP-CRON

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit