
OWASP-mth3l3m3nt-framework
OWASP Mth3l3m3nt Framework is a penetration testing aiding tool and exploitation framework. It fosters a principle of attack the web using the web as…

OWASP Mth3l3m3nt Framework is a penetration testing aiding tool and exploitation framework. It fosters a principle of attack the web using the web as…

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

Google Chrome CVE-2026-6307 PoC

一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率

CVE-2026-8452 PreAuth RCE

Script to automate PUT HTTP method exploitation to get shell

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Decrypted content of eqgrp-auction-file.tar.xz

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

Foxit PDF Reader Remote Code Execution Exploit

CVE-2023-2255 Libre Office

WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit

Palo Alto - CVE-2026-0300 exploit

PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell

OpenSTAManager RCE Exploit (CVE-2026-38751)

这里保存着我学习CVE-2012-1889这个漏洞的利用所用到的文件