
put2win
Script to automate PUT HTTP method exploitation to get shell

Script to automate PUT HTTP method exploitation to get shell

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

This repository contains a python script that will handle the majority of the dompdf cached font exploit (CVE-2022-28368), all you need to do is…

Custom CAB template generator for CVE-2021-40444, crafting malicious cabinet archives to exploit Windows MSHTML remote code execution via crafted…

Google Chrome CVE-2026-6307 PoC

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

a exp for cve-2018-9948/9958 , current shellcode called win-calc

Suite for reverse shell handling geared toward working within the native shell

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

Bassmaster Plugin NodeJS RCE

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Foxit PDF Reader Remote Code Execution Exploit

CVE-2026-8452 PreAuth RCE

CVE-2023-2255 Libre Office

WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit

PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…