
Loki
🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

Exploit scripts for CVE-2025-62507, a stack buffer overflow in Redis 8.2.0. Provides x86-64 and ARM64 ROP chain exploits with shellcode generation…

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

CVE-2013-2028 python exploit

Proof-of-concept exploit for CVE-2023-38831 targeting vulnerable versions, delivering a reverse shell via automated exploitation.

CVE-2020-15368, aka "How to exploit a vulnerable driver"

Python exploit for CVE-2019-11447 that uploads a PHP reverse shell to CuteNews 2.1.2, enabling remote command execution on vulnerable web…

Unauthenticated 0-click RCE exploit for CVE-2024-50526. Exploits an arbitrary file upload vulnerability in a vulnerable WordPress form plugin to…

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

MS08-067 | CVE-2008-4250

Educational proof-of-concept demonstrating CVE-2026-31431 with a vulnerable target application, demonstration payload, and shellcode extraction…

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

WordPress Processing Projects Plugin <= 1.0.2 is vulnerable to Arbitrary File Upload

Proof-of-concept exploit for CVE-2024-6387 targeting vulnerable OpenSSH servers via heap manipulation and race condition to achieve remote code…

SMTP vulnerability scanner and exploit script that checks for CVE-2024-45519 and establishes a reverse shell on vulnerable servers.

Mass exploit for CVE-2024-25600, uploading webshells to vulnerable WordPress sites via a list of targets.

STACK BUFFER OVERFLOW EXPLOIT RESULTING IN REMOTE CODE EXECUTION

Script to exploit CVE-2023-38035