
pritunl
Provides distributed enterprise VPN connectivity using OpenVPN, with centralized management, authentication, and encrypted tunnels for cloud and…

Provides distributed enterprise VPN connectivity using OpenVPN, with centralized management, authentication, and encrypted tunnels for cloud and…

Python implementation of OpenPsPipeJack

A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

Remote Desktop Protocol .NET Console Application for Authenticated Command Execution

CVE Reproduction: cve-2024-38077-madlicense_reproduction

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

CVE-2026-6508 LiderAhenk Merkezi Yönetim Sistemi mimarisinde, uç birimler (agents) arası tüm istemcilerin birbirleri üzerinde 'root' yetkisiyle kod…

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。

DCOM in memory and fileless lateral movement techniques through .Net deserilization

Apache ActiveMQ RCE via Jolokia vulnerability analysis and reproduction notes

React2Shell (CVE-2025-55182) Exploit

WebStack <= 1.2024 - Unauthenticated Arbitrary File Upload

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Browser-based CVE-2021-21220 exploit delivering a reverse shell via shellcode and a C2 implant for remote command execution on Windows targets.

A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.

psexecsvc - a python implementation of PSExec's native service implementation

Pre-authentication remote code execution exploit for React Server Components and Next.js via deserialization vulnerability. Supports single-target…