
CVE-2026-24061-POC
Proof-of-concept exploit for CVE-2026-24061 providing an interactive remote shell session with configurable timeouts for reliable exploitation.

Proof-of-concept exploit for CVE-2026-24061 providing an interactive remote shell session with configurable timeouts for reliable exploitation.

Automated exploit for CVE-2025-59287, an unauthenticated RCE in WSUS, featuring payload generation, reverse shell listener, and AES encryption with…

Exploit for CVE-2025-52136 enabling RCE on EMQX control panel via plugin upload, with MQTT-based command agent and SOCKS5 tunnel for out-of-band C2…

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

Ruby-based exploit for CVE-2026-24061 that executes arbitrary commands on remote targets, supporting multi-threaded scanning and command injection…

Provides distributed enterprise VPN connectivity using OpenVPN, with centralized management, authentication, and encrypted tunnels for cloud and…

Python implementation of OpenPsPipeJack

A basic emulation of an "RPC Backdoor"

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

psexecsvc - a python implementation of PSExec's native service implementation

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

Firecat is a penetration testing tool that allows you to punch reverse TCP tunnels out of a compromised network.

A SOCKS proxy for Citrix.

SOCKS proxy for port forwarding and RDP tunneling, enabling lateral movement and remote access in penetration testing scenarios.

Generates TeamViewer ID and password payloads for remote access to target machines. Combines executable generation with third-party remote control…

WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload

Pre-authentication remote code execution exploit for React Server Components and Next.js via deserialization vulnerability. Supports single-target…

CVE Reproduction: cve-2024-38077-madlicense_reproduction