
EQGRP
Collection of leaked NSA Equation Group exploits, backdoors, and tools for post-exploitation, privilege escalation, and command-and-control across…

Collection of leaked NSA Equation Group exploits, backdoors, and tools for post-exploitation, privilege escalation, and command-and-control across…

Generates PowerShell-based shellcode injection payloads for memory execution, supporting Metasploit, Cobalt Strike, and custom shellcode via macro,…

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Web-based penetration testing framework with LFI exploitation, shell generation, payload encoding, HTTP bot herd C2, and cookie theft modules for…

Compile Go and C# programs into WASM-sandboxed native executables with polymorphic output, ghost profiling, and transparent Win32/macOS API bridging…

Script to automate PUT HTTP method exploitation to get shell

Foxit PDF Reader Remote Code Execution Exploit

Python-based proof-of-concept exploit for CVE-2023-2255 (LibreOffice RCE) that generates malicious ODT files to drop a webshell via arbitrary command…

Proof-of-concept exploit for Citrix NetScaler CVE-2026-8452 that verifies pre-auth RCE by building shellcode and executing commands through a…

Weaponized PoC for CVE-2026-6307, a V8 JS-to-Wasm type confusion causing Chrome renderer RCE; includes flag-free addrof/fakeobj primitives and…

Multi-CVE WebLogic deserialization exploit builder with support for process builder, serialized, and URL-based payloads, enabling remote command…

PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

Personal learning repository for CVE-2012-1889 exploitation, containing exploit HTML, shellcode converters, debugger tools, and ROP chain generation…

Proof-of-concept exploit for CVE-2019-11707, a SpiderMonkey type confusion vulnerability enabling arbitrary read/write and JIT spray-based shellcode…

Proof-of-concept exploit for CVE-2025-3969 providing OS command injection, web shell, and interactive shell capabilities for penetration testing.