
CVE-2019-18276
Demonstration exploit for CVE-2019-18276, a local privilege escalation vulnerability in Bash, using a crafted shared library to gain root access.

Demonstration exploit for CVE-2019-18276, a local privilege escalation vulnerability in Bash, using a crafted shared library to gain root access.

DirtyPipe (CVE-2022-0847) exploit written in Rust

Offensive Software Exploitation Course


EXOCET - AV-evading, undetectable, payload delivery tool

:cherry_blossom: Interactive shellcoding environment to easily craft shellcodes

A Fully Undetectable C2 Server That Communicates Via Google SMTP to evade Antivirus Protections and Network Traffic Restrictions

Evaluation framework for studying LLM agents that automatically generate working exploits from vulnerability reports, bypassing modern security…

An Bash&Python Script For Generating Payloads that Bypasses All Antivirus so far [FUD]

Go package that aids in binary analysis and exploitation

Header-only C++2x compile-time assembler for x86/x86-64 instruction encoding

Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.

Atlassian Jira unauthen template injection

Hands-on lab reproducing CVE-2025-22457: sets up Docker attacker/victim containers, finds stack addresses with GDB, and delivers a msfvenom reverse…

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

Easy-to-understand version of CVE-2026-31431

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…