
CVE-2025-32432-exploit-by-P34NUT
Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

Python PoC exploiting CVE-2024-2044 in pgAdmin 4 (<=8.3) via authenticated path traversal and unsafe pickle deserialization to achieve remote code…

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Exploit for CVE-2026-41940 providing direct shell access via websocket and persistence through root API key injection.

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

A cross platform C2/post-exploitation framework.

REC2 (Rusty External Command and Control) is client and server tool allowing auditor to execute command from VirusTotal and Mastodon APIs written in…

Metasploit AV Evasion Tool

Proof-of-concept backdoor for SCCM Management Point using rogue COM service for persistent remote command execution as SYSTEM.


Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.

PyRat,a rat by python xmlrpc


CVE-2024-49375、CVE-2021-42556、CVE-2021-41127

TinySHell port to SCTP

PowerShell to Slack C2

a open source remote administrator tool