
cve-2022-29464
Python exploit for CVE-2022-29464 targeting WSO2 web servers with automated webshell upload and command execution capabilities.

Python exploit for CVE-2022-29464 targeting WSO2 web servers with automated webshell upload and command execution capabilities.

Proof-of-concept remote code execution exploit for Safari 11.0.3 on macOS 10.13.3, leveraging a WebAssembly section vulnerability with heap spray and…

Proof-of-concept exploit for Apache Tomcat CVE-2025-24813, demonstrating remote code execution via partial PUT and deserialization. Includes Docker…

Python exploit for Spring Framework CVE-2022-22965 remote code execution with webshell deployment and Burp payload support for penetration testing.

Automated exploit for CVE-2024-23740 targeting Kap on macOS. Injects code via RunAsNode and enableNodeClilnspectArguments to spawn a remote shell.

Automated exploit for CVE-2024-23741 targeting Hyper on macOS. Validates vulnerability and injects code to spawn a remote shell via RunAsNode and…

PS5 exploit chain for firmware 7.00-13.60 combining a WebKit JSC info leak and typedarray corruption with an aio_multi_wait UAF race for kernel…

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Nano is a family of PHP web shells which are code golfed for stealth.

Compromising the macOS Kernel through Safari by Chaining Six Vulnerabilities

Herramienta para evadir disable_functions y open_basedir

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Public repository for improvements to the EXTRABACON exploit

RCE exploit for CVE-2023-3519

pinky - The PHP mini RAT (Remote Administration Tool)

Win32k Exploit by Grant Willcox

Google Chrome CVE-2026-6307 PoC

MS Word MS WordPad via IE VBS Engine RCE