
CVE-2026-48907
CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

Google Chrome CVE-2026-6307 PoC

Proof-of-concept exploit for CVE-2021-38001, a Chrome V8 JavaScript engine vulnerability, demonstrating remote code execution via crafted .mjs files.

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Full-chain RCE exploit for CVE-2025-2783, a Chromium Ipcz sandbox escape vulnerability. Implements thread hijacking, V8 hooks, and shellcode…

ImaegMagick Code Execution (CVE-2016-3714)

Proof-of-concept exploit for CVE-2018-17463 demonstrating arbitrary code execution in Chrome via V8 side-effect annotation bug, using WebAssembly RWX…

Exploit for CVE-2026-11645, a V8 out-of-bounds read/write in Google Chrome allowing remote code execution via crafted HTML pages.

Collection of pentesting scripts

Full-chain Chrome exploit targeting CVE-2019-5782 and CVE-2019-13768 with custom ROP gadgets and shellcode for arbitrary command execution on Windows…

Proof-of-Concept exploit for CVE-2025-14174 (EUVD-2025-203113) - Memory corruption in ANGLE allowing out-of-bounds access and RCE in web browsers.…

Browser-based CVE-2021-21220 exploit delivering a reverse shell via shellcode and a C2 implant for remote command execution on Windows targets.

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.


Chained Chrome V8 renderer escape proof-of-concept exploiting four CVEs: Float64Array corruption, Wasm overwrite, popup navigation retargeting, and…

pinky - The PHP mini RAT (Remote Administration Tool)