
sshuttle
Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS…

Proof-of-concept exploit for CVE-2020-25223 (Sophos UTM web admin pre-auth RCE) that delivers a reverse shell. Includes post-exploitation notes and…

Authenticated EL injection exploit for GlassFish/Payara admin console enabling remote command execution via crafted parameters in the virtual server…

Exploit for CVE-2026-15013: unauthenticated SAML auth bypass via algorithm confusion. Forges SAML responses to gain admin access and deploy…

Alex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File Upload

Proof-of-concept exploit for CVE-2021-24307, an authenticated admin RCE in All in One SEO Pack <= 4.1.0.1 via PHP unserialization, enabling arbitrary…

AIO Cloud Managment Server

Exploit script for CVE-2023-24249 - a vulnerability allowing remote code execution via file upload and command injection.

CVE-2020-14008 - ManageEngine Applications Manager RCE

Open Web Analytics 1.7.3 - Remote Code Execution

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

Python Exploit for CVE: 2018-9276

Exploit for CVE-2021-43857 in Gerapy v0.9.7, providing a reverse shell via authenticated project creation and command injection.

Open-Source Remote Administration Tool For Windows C# (RAT)

Basic Multiplatform Remote Administration Tool - Xamarin

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

CVE-2019-1040 with Kerberos delegation