
CVE-2025-34096
SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.

SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.

A Proof of Concept for CVE-2023-50564 vulnerability in Pluck CMS version 4.7.18

PowerSploit - A PowerShell Post-Exploitation Framework

Exploit for CVE-2024-23897 in Jenkins, enabling file read and remote code execution via crafted requests. Includes Docker setup and Groovy scripts…

Python exploit for CVE-2025-7340, an unauthenticated file upload vulnerability in the WordPress HT Contact Form widget, enabling remote code…

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

WordPress Processing Projects Plugin <= 1.0.2 is vulnerable to Arbitrary File Upload

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

RCE Exploit and Research

Automated scanner and exploit for CVE-2025-34085, an unauthenticated RCE in the WordPress Simple File List plugin. Supports multi-target scanning,…

My experiments in weaponizing Nim (https://nim-lang.org/)

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

bin2shell is very small utils for extract shell code from the binary file

Hijacks code execution via overwriting Control Flow Guard pointers in combase.dll

Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4061 - JobBoardWP < 1.2.2 - Unauthenticated Arbitrary File Upload

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

Python-based proof-of-concept exploit for CVE-2017-8367, a stack-based buffer overflow in Easy Mov Converter. Generates a payload file for local…