
XeytanWin32-RAT
WORK IN PROGRESS. RAT written in C++ using Win32 API

WORK IN PROGRESS. RAT written in C++ using Win32 API

A fully featured Windows backdoor that uses email as a C&C server

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

Evince/xreader/Atril RCE exploit to CVE-2026-46529

Work in Progress. RAT written in C++ using wxWidgets

IKEv2, ikeext.dll, CVE-2026-33824, double free, heap grooming, ROP, SKF fragmentation, Windows exploit, anti-debug, obfuscation, API hooking,…

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

React Server Components 远程代码执行漏洞(CVE-2025-55182)

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered…


CVE-2014-6287

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Full-chain exploit for CVE-2025-2783 (Ipcz Sandbox Escape & RCE).

Python-based exploit for CVE-2019-2725 (Oracle WebLogic) providing command execution and webshell upload targeting versions 10.3.6 and 12.1.3.