
CVE-2026-102425
GUI scanner and exploit for CVE-2026-102425, an unauthenticated RCE in Balbooa Forms (com_baforms) via PHP shortcode injection, with mass scanning…

GUI scanner and exploit for CVE-2026-102425, an unauthenticated RCE in Balbooa Forms (com_baforms) via PHP shortcode injection, with mass scanning…

Python proof-of-concept for CVE-2026-44011 in Craft CMS, exploiting authenticated remote code execution with command execution and base64-wrapped…

Python exploit tool chaining CVE-2026-63030 REST batch-route confusion with CVE-2026-60137 SQL injection to achieve unauthenticated WordPress RCE,…

PyIris is a modular remote access trojan toolkit written in python targeting Windows and Linux systems.

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

Claude Code Remote Code Execution

Tools for maintaining access to systems and proof-of-concept demonstrations.

CROSS PLATFORM REMOTE ACCESS TROJAN (RAT)

Modern PIC implant for Windows (64 & 32 bit)

Exploit For SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)

This is a webshell open source project

xll windows reverse shell

🔥 CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems.

CHAOS RAT web panel path RCE PoC

Source code for SubSeven 2.1.3

A Python based RAT 🐀 (Remote Access Trojan) for getting reverse shell 🖥️