
CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.

Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.

Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with…

A tool to abuse Exchange services

Go shellcode loader that combines multiple evasion techniques

Execute shellcode files with rundll32

PostShell - Post Exploitation Bind/Backconnect Shell

Win32k Exploit by Grant Willcox

Yet Another PHP Shell - The most complete PHP reverse shell

spring4shell | CVE-2022-22965

HRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.

Safari 1day RCE Exploit

Proof-of-concept exploit for authenticated PHP code injection in ISPConfig <= 3.2.11, enabling remote code execution via unsanitized language file…

Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

C++ memshell DLL generator for CVE-2019-18935, enabling in-memory web shell deployment via Telerik UI deserialization with Assembly.Load and IJW…

Repository containing exploit scripts for various CVEs, targeting web applications, binaries, and network services, suitable for penetration testing…

Exploit for CVE-2019-16278 targeting Nostromo Web Server 1.9.6, achieving remote code execution via directory traversal. Uses pwntools to deliver a…

Python exploit for CVE-2022-29464 targeting WSO2 web servers with automated webshell upload and command execution capabilities.