
EQGRP
Collection of leaked NSA Equation Group exploits, backdoors, and tools for post-exploitation, privilege escalation, and command-and-control across…

Collection of leaked NSA Equation Group exploits, backdoors, and tools for post-exploitation, privilege escalation, and command-and-control across…

Generates PowerShell-based shellcode injection payloads for memory execution, supporting Metasploit, Cobalt Strike, and custom shellcode via macro,…

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Web-based penetration testing framework with LFI exploitation, shell generation, payload encoding, HTTP bot herd C2, and cookie theft modules for…

Proof-of-concept exploit for Citrix NetScaler CVE-2026-8452 that verifies pre-auth RCE by building shellcode and executing commands through a…

Script to automate PUT HTTP method exploitation to get shell

Foxit PDF Reader Remote Code Execution Exploit

Compile Go and C# programs into WASM-sandboxed native executables with polymorphic output, ghost profiling, and transparent Win32/macOS API bridging…

Weaponized PoC for CVE-2026-6307, a V8 JS-to-Wasm type confusion causing Chrome renderer RCE; includes flag-free addrof/fakeobj primitives and…

Python-based proof-of-concept exploit for CVE-2023-2255 (LibreOffice RCE) that generates malicious ODT files to drop a webshell via arbitrary command…

Multi-CVE WebLogic deserialization exploit builder with support for process builder, serialized, and URL-based payloads, enabling remote command…

Exploit toolkit for PAN-OS Captive Portal CVE-2026-0300 with a version-aware scanner, version-specific payload generator, and detection/crash/RCE…

PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

Python exploit for CVE-2026-38751 enabling authenticated remote code execution on OpenSTAManager 2.10 via malicious module upload, with interactive…

Personal learning repository for CVE-2012-1889 exploitation, containing exploit HTML, shellcode converters, debugger tools, and ROP chain generation…