
Webmin-CVE-2022-0824-Enhanced-Exploit
Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

Suite for reverse shell handling geared toward working within the native shell

Google Chrome CVE-2026-6307 PoC

Palo Alto - CVE-2026-0300 exploit

Proof-of-concept exploit for Citrix NetScaler CVE-2026-8452 that verifies pre-auth RCE by building shellcode and executing commands through a…

Decrypted content of eqgrp-auction-file.tar.xz

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

OWASP Mth3l3m3nt Framework is a penetration testing aiding tool and exploitation framework. It fosters a principle of attack the web using the web as…

Script to automate PUT HTTP method exploitation to get shell

Foxit PDF Reader Remote Code Execution Exploit

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

CVE-2023-2255 Libre Office

WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit

PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

OpenSTAManager RCE Exploit (CVE-2026-38751)