
watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
Proof-of-concept exploit for Citrix NetScaler CVE-2026-8452 that verifies pre-auth RCE by building shellcode and executing commands through a…

Proof-of-concept exploit for Citrix NetScaler CVE-2026-8452 that verifies pre-auth RCE by building shellcode and executing commands through a…

Exploit toolkit for PAN-OS Captive Portal CVE-2026-0300 with a version-aware scanner, version-specific payload generator, and detection/crash/RCE…

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

Python exploit for CVE-2026-38751 enabling authenticated remote code execution on OpenSTAManager 2.10 via malicious module upload, with interactive…

Weaponized PoC for CVE-2026-6307, a V8 JS-to-Wasm type confusion causing Chrome renderer RCE; includes flag-free addrof/fakeobj primitives and…

Compile Go and C# programs into WASM-sandboxed native executables with polymorphic output, ghost profiling, and transparent Win32/macOS API bridging…

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Generates PowerShell-based shellcode injection payloads for memory execution, supporting Metasploit, Cobalt Strike, and custom shellcode via macro,…

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

Proof-of-concept exploit for CVE-2025-3969 providing OS command injection, web shell, and interactive shell capabilities for penetration testing.

Proof-of-concept exploit for CVE-2021-30632, a Chrome V8 vulnerability, demonstrating reliable shellcode execution via out-of-bounds write to achieve…

Foxit PDF Reader Remote Code Execution Exploit

Python-based proof-of-concept exploit for CVE-2023-2255 (LibreOffice RCE) that generates malicious ODT files to drop a webshell via arbitrary command…

This repository contains a python script that will handle the majority of the dompdf cached font exploit (CVE-2022-28368), all you need to do is…

Python proof-of-concept exploit for CVE-2014-7205, a remote code execution vulnerability in the Bassmaster plugin for NodeJS, including a reverse…

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit