
poc-CVE-2026-64638-
PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

Hide your payload into .jpg file

Lnk crafting and research tools

Inject DLLs into the explorer process using icons

PoC exploit for CVE-2023-52076 - zip-slip path traversal in Atril/Xreader (MATE/Cinnamon) enabling arbitrary file write and RCE via crafted EPUB.…

Loki.Rat is a fork of the Ares RAT, it integrates new modules, like recording , lockscreen , and locate options. Loki.Rat is a Python Remote Access…

A tool to transform Chromium browsers into a C2 Implant

evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)

Whatsapp Automatic Payload Generator [CVE-2019-11932]

This is a Automated Generate Payload for CVE-2019-11932 (WhatsApp Remote Code Execution)

This demonstration video shows how we can control the victim's device by sending the innocent-looking PDF file to the target which actually consists…

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

transform your payload.exe into one fake word doc (.ppt)

Embed and hide any file in an HTML file

Use a Fake image.jpg to exploit targets (hide known file extensions)

Trojanize your payload - WinRAR (SFX) automatization - under Linux distros