
CVE-2026-34197
Apache ActiveMQ RCE via Jolokia vulnerability analysis and reproduction notes

Apache ActiveMQ RCE via Jolokia vulnerability analysis and reproduction notes

CVE-2019-16278 Python3 Exploit Code

Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

The Shadow Attack Framework

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

Hijack Putty sessions in order to sniff conversation and inject Linux commands.

psexecsvc - a python implementation of PSExec's native service implementation

DCOM in memory and fileless lateral movement techniques through .Net deserilization

A basic emulation of an "RPC Backdoor"

A Ligolo-ng JavaScript agent working inside Chrome & Chromium-based browsers by leveraging Isolated Web Applications.

Proof of conept to exploit vulnerable proxycommand configurations on ssh clients (CVE-2023-51385)

Python implementation of OpenPsPipeJack

A Windows Remote Administration Tool in Visual Basic with UNC paths

Python script that patches the termsrv.dll file on Windows to enable multiple concurrent RDP sessions, supporting Windows 10 versions 1703 through…

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…

CVE-2026-6508 LiderAhenk Merkezi Yönetim Sistemi mimarisinde, uç birimler (agents) arası tüm istemcilerin birbirleri üzerinde 'root' yetkisiyle kod…