
PHP-REVERSE-SHELL
This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

GitPwnd is a network penetration tool that lets you use a git repo for command and control of compromised machines

PeekABoo tool can be used during internal penetration testing when a user needs to enable Remote Desktop on the targeted machine. It uses PowerShell…

Exploitation toolkit for CVE-2026-22812 (OpenCode unauthenticated RCE) providing interactive shell, arbitrary command execution, file…

Exploit tool targeting CVE-2019-0708 in Remote Desktop Services, enabling remote code execution on vulnerable Windows systems for penetration testing…

This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server.…

F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB

Pre-authentication remote code execution exploit for Oracle WebLogic ADF Faces (CVE-2022-21445, CVSS 9.8). Includes detailed environment setup,…

Technical penetration testing writeup demonstrating exploitation of CVE-2025-55182 in Next.js, credential harvesting from SQLite, and privilege…

Automates exploitation of CVE-2020-13160, a critical remote code execution vulnerability in AnyDesk 5.5.2, enabling penetration testers to validate…

Exploit for CVE-2019-0708 (BlueKeep) targeting Remote Desktop Services on legacy Windows systems, enabling remote code execution for penetration…

Go-based proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components. Features vulnerability checking, command execution, memory…

Proof-of-concept exploit for CVE-2020-16898, a Windows TCP/IP remote code execution vulnerability. Includes Python-based exploit scripts targeting…

Python exploit for Craft CMS CVE-2023-41892 Remote Code Execution vulnerability, delivering a PHP reverse shell for authorized penetration testing.

Python 3 exploit for FuelCMS 1.4.1 Remote Code Execution (CVE-2018-16763). Unauthenticated RCE via crafted HTTP requests for penetration testing and…

Exploit for Marimo pre-auth RCE via terminal WebSocket, providing command execution, interactive PTY shell, and reverse shell capabilities for…

Exploit for CVE-2026-63077, an unauthenticated RCE in JetBrains TeamCity via deserialization. Supports mass scanning, multi-threading, and…