
XSS2Shell
Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Exploits CouchDB CVE-2017-12635/12636 for privilege escalation and RCE, then provides an interactive shell with command execution, database browsing,…

Asynchronous RDP client for Python (headless)

Modern tactical exploitation toolkit.

New generation of wmiexec.py

Hooked browser communication over MQTT

A command shell wrapper using only WMI for Microsoft Windows

Intranet penetration tools

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability

CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

Xenotix xBOT is a Cross Platform PoC Bot that abuse certain Google Services to implement it's C&C

complex webshell manager, quasi-http botnet.

[WIP]RemoteAssistance like TeamViewer(C++)

Work in Progress. RAT written in C++ using wxWidgets

This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is…

CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit

CVE-2024-6387