

An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits

Stack-based buffer overflow in the server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to cause a denial of…

Framework for generating shellcode and exploit payloads, designed for penetration testing and security research to automate payload creation and…

A Ruby framework designed to aid in the penetration testing of WordPress systems.

Curated collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for penetration testing and educational offensive…

Authenticated remote code execution exploit for PlaySMS 1.4 via CSV phonebook upload. Provides single-command and interactive shell modes for…

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

Exploit and scanner for CVE-2024-6387 (regreSSHion) in OpenSSH. Includes detection, RCE exploitation, and shellcode generation for authorized…

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

Proof-of-concept exploit for CVE-2025-49132 delivering a reverse shell. Includes customizable host/listener variables and clean output for…

Python exploit script for CVE-2022-41544 in GetSimple CMS. Automates API key leakage, CSRF token extraction, PHP shell upload, and reverse shell…

Exploit for CVE-2018-20250 (WinRAR ACE path traversal) with automated payload generation and Metasploit reverse shell integration for penetration…

Python exploit for Spring Framework CVE-2022-22965 remote code execution with webshell deployment and Burp payload support for penetration testing.

Automated exploit tool targeting CVE-2024-52010 for penetration testing and vulnerability validation.

CVE-2024-10914 Shell Exploit