
CVE-2026-95675
Python PoC exploiting CVE-2026-95675, an unauthenticated root command injection in D-Link DAP-1360 RevB firmware via a hardcoded auth-bypass and the…

Python PoC exploiting CVE-2026-95675, an unauthenticated root command injection in D-Link DAP-1360 RevB firmware via a hardcoded auth-bypass and the…

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Proof-of-concept exploit for CVE-2026-30368, demonstrating authentication bypass in Lightspeed Classroom to control student devices via Ably channel.

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

SubSeven Legacy Official Source Code Repository

A cross platform C2/post-exploitation framework.

Our Friendly Gmail will act as Server and implant will exfiltrate data via smtp and will read commands from C2 (Gmail) via imap protocol

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

Generates TeamViewer ID and password payloads for remote access to target machines. Combines executable generation with third-party remote control…

phpstudy dll backdoor for v2016 and v2018

AdaptixC2 is a highly modular advanced redteam toolkit


PCShare是一款强大的远程控制软件,可以监视目标机器屏幕、注册表、文件系统等。

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).

A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.

NyxInvoke is a Rust CLI tool for running .NET assemblies, PowerShell, and BOFs with Patchless AMSI and ETW bypass features. with Dual-build support

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service