
Exploit-CVE-2024-23897
Exploit for CVE-2024-23897 in Jenkins, enabling file read and remote code execution via crafted requests. Includes Docker setup and Groovy scripts…

Exploit for CVE-2024-23897 in Jenkins, enabling file read and remote code execution via crafted requests. Includes Docker setup and Groovy scripts…

Proof-of-concept exploit for Apache Tomcat CVE-2025-24813, demonstrating remote code execution via partial PUT and deserialization. Includes Docker…

A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".

With the help of this docker image, you can easily access PEzor on your system!

Some setup scripts for security research tools.

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Builds a shell.so reverse shell payload for CVE-2025-1974 (IngressNightmare) using Alpine Linux in Docker, with hardcoded IP and port configuration.

Python AV Evasion Tools

Proof-of-concept exploit for CVE-2024-10793 targeting WordPress wp-security-audit-log plugin. Demonstrates account takeover, privileged user…

Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell…

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

Undetectable Windows Payload Generation

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

Reflective PE packer.

Nim-based assembly packer and shellcode loader for opsec & profit