
weevely3
Weaponized web shell

Weaponized web shell

Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)


JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…


Proof on Concept Exploit for CVE-2021-38647 (OMIGOD)

RCE on Apache Solr using deserialization of untrusted data via jmx.serviceUrl

Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE

Exploit for WebSocket Vulnerability in Apache Tomcat


CVE-2024-21683 Confluence Post Auth RCE

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.


Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575

SpringBoot_Actuator_RCE

PoC for the CVE-2022-41080 , CVE-2022-41082 and CVE-2022-41076 Vulnerabilities Affecting Microsoft Exchange Servers

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)