
DbgNexum
Shellcode injection using the Windows Debugging API

Shellcode injection using the Windows Debugging API

Polymorphic shellcode generator for in-memory execution of EXE, DLL, .NET, VBScript, and JScript with per-output and per-build randomization for…

This repository contains a python script that will handle the majority of the dompdf cached font exploit (CVE-2022-28368), all you need to do is…

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

CVE-2023-2255 Libre Office

Custom CAB template generator for CVE-2021-40444, crafting malicious cabinet archives to exploit Windows MSHTML remote code execution via crafted…

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit

PoC for Forgot2kEyXCHANGE (CVE-2020-0688) written in PowerShell

CVE-2026-38526 exploit for Krayin CRM v2.2.x - Authenticated RCE via TinyMCE file upload bypass. Features interactive shell, multi-type payloads,…

## 在kali中自动化生成cve-2017-8570的恶意ppsx文件和配置msf监听

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

OpenSTAManager RCE Exploit (CVE-2026-38751)

CVE-2025-3969: Exploit PoC (OS CMD injection, Web Shell, Interactive Shell)

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

Python exploit for Webmin CVE-2022-0824 with dual-mode support: direct command execution and reverse shell. Features multiple payload types,…

a exp for cve-2018-9948/9958 , current shellcode called win-calc

Bassmaster Plugin NodeJS RCE