
Copy-Fail-CVE-2026-31431-modernized
Proof-of-concept exploit for CVE-2026-31431, modernized from the original Copy Fail PE exploit. Demonstrates the vulnerability for educational…

Proof-of-concept exploit for CVE-2026-31431, modernized from the original Copy Fail PE exploit. Demonstrates the vulnerability for educational…

Microsoft just released emergency patches for CVE-2026-21509, a zero-day in the Office Suite that bypasses OLE/COM mitigations when a user simply…

It's a CRLF injection in Mailpit's SMTP server — a classic data corruption vulnerability. But under CTT, it's not just a bug. It's a phase…

A wrapper around grep, to help you grep for things

just record for myself

Exploits CVE-2026-39987 pre-auth RCE in Marimo <0.23.0 by connecting to the unauthenticated /terminal/ws WebSocket. Supports arbitrary command…

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

Stock vulnerable wordpress RCE poc for wp2shell.

This is a simple Shiro-basic project .Just for pentest env

Python Implementation of a .NET Padding Oracle Assessment Tool

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

ipfire 2.25 authenticated remote code execution

PHP shells that work on Linux OS, macOS, and Windows OS.

Educational PDF files demonstrating client-side exploitation techniques, including calculator execution and directory browsing, for security testing…


Exploit for WP BookingPress (< 1.0.11) based on destr4ct POC.

cve-2020-0688 UNIVERSAL Python implementation utilizing ASPX webshell for command output

Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR