
SecureForce
A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing

A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing

Provides a bash workaround script to mitigate CVE-2026-31431, preventing remote code execution via copy.fail exploit. Includes usage instructions for…

基于Java实现的Shellcode加载器

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

A simple ptrace-less shared library injector for x64 Linux

A third-party Gopher Assassin for the Havoc Framework.

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

A small, null-free Windows shellcode that executes calc.exe (x86/x64, all OS/SPs)

Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86-64, x86,…

Repository containing exploit scripts for various CVEs, targeting web applications, binaries, and network services, suitable for penetration testing…

A Bash implementation of copyfail (CVE-2026-31431)

ASUSTOR ADM 5.1.2 vpnupload.cgi Format String & Stack Buffer Overflow RCE (CVE-2026-6643)

Python exploit for Spring Framework CVE-2022-22965 remote code execution with webshell deployment and Burp payload support for penetration testing.

Free MP3 CD Ripper 2.6 版本中存在栈缓冲区溢出漏洞 (CVE-2019-9766),远程攻击者可借助特制的 .mp3 文件利用该漏洞执行任意代码。

CVE-2025-55182漏洞检测工具

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities