
etaHEN
PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

Alex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File Upload

Exploit for CVE-2026-15013: unauthenticated SAML auth bypass via algorithm confusion. Forges SAML responses to gain admin access and deploy…

Open-Source Remote Administration Tool For Windows C# (RAT)

Basic Multiplatform Remote Administration Tool - Xamarin

Exploit for CVE-2021-27651: bypasses Pega Infinity password reset flow to reset any user's password, enabling admin login and subsequent remote code…

Authenticated EL injection exploit for GlassFish/Payara admin console enabling remote command execution via crafted parameters in the virtual server…

Self-hosted WireGuard mesh VPN with browser-based admin portal, Winbox proxy, WebSSH, and WebProxy for managing remote devices and IoT infrastructure…

Exploit script for CVE-2023-24249 - a vulnerability allowing remote code execution via file upload and command injection.

Open Web Analytics 1.7.3 - Remote Code Execution

Exploit for CVE-2018-14324 achieving RCE on Eclipse GlassFish 5 via JMX MLet MBean with hardcoded admin credentials, using Beanshooter for stager…

Proof-of-concept exploit for CVE-2020-25223 (Sophos UTM web admin pre-auth RCE) that delivers a reverse shell. Includes post-exploitation notes and…

Authenticated remote code execution exploit for FuguHub 8.4, injecting a Lua reverse shell via the customizable About page in the admin panel.

Proof-of-concept exploit for CVE-2025-66398 targeting Signal K Server ≤ 2.18.0. Performs unauthenticated state pollution, backdoor admin injection,…

Exploit for CVE-2021-43857 in Gerapy v0.9.7, providing a reverse shell via authenticated project creation and command injection.

Exploit scripts for CVE-2023-42793 in JetBrains TeamCity, enabling admin account creation and remote code execution with reverse shell support.

Exploit scripts for WonderCMS 4.3.2 that chain XSS to RCE by injecting a crafted theme payload and triggering a reverse shell from the admin session.

Python tool exploiting CVE-2019-1040 to perform Kerberos delegation attacks, enabling relay attacks for RCE and domain admin compromise.