
postshell
PostShell - Post Exploitation Bind/Backconnect Shell

PostShell - Post Exploitation Bind/Backconnect Shell

A stealthy stager designed for shellcode payloads staged with http/https like Sliver, or on github raw.

Win32k Exploit by Grant Willcox

SpringFramework 远程代码执行漏洞CVE-2022-22965

rce

takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities

Nim-based process hollowing loader for PE executables with configurable injection methods, direct/indirect syscalls, anti-debug, payload encryption,…

PoC for CVE-2025-22457 - A remote unauthenticated stack based buffer overflow affecting Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy…

Google Chrome Use After Free

An exploit for CVE-2019-17026. It pops xcalc and was tested on Ubuntu (x64).

CVE-2017-13089

Apache Tomcat Manager API WAR Shell Upload

SMTP vulnerability scanner and exploit script that checks for CVE-2024-45519 and establishes a reverse shell on vulnerable servers.

Simple dotnet Native AOT app that uses AsmResolver to convert shellcode to PE

WonderCMS Authenticated RCE - CVE-2023-41425

Laravel RCE exploit. CVE-2018-15133

Python-based exploit for CVE-2022-22965 (Spring4Shell) with vulnerability detection and webshell injection (Behinder/Godzilla) into Spring web…

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…