
Fritter
Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell…

CVE-2024-36401 exploit with webshell-like functionality for limited environments, supporting self-signed TLS sessions and remote command execution…

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

CVE-2023-46604-RCE exploit with Linux reverse shell payload

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Magento APSB25-94 Unauthenticated File Upload to RCE (CVE-2026-XXXX) - Eval Shell + Probe Scanner

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

A PICO for Crystal Palace that implements CLR hosting to execute a .NET assembly in memory.

Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute…

Unauthenticated 0-click RCE exploit for CVE-2024-50526. Exploits an arbitrary file upload vulnerability in a vulnerable WordPress form plugin to…

posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)

Python-based exploit for CVE-2018-2628 targeting Oracle WebLogic Server, providing vulnerability detection and remote shell access via JSP payload…

This script exploits CVE-2025-62369 in Xibo CMS to execute a reverse shell command.

POC exploit for Dolibarr <= 17.0.0 (CVE-2023-30253)

Exploit for CVE-2024-39205, a js2py sandbox escape that enables remote code execution and establishes a reverse shell.

VulnCheck CVE-2025-55182 react2shell

Reverse shell for CVE-2024-28397.