
backcookie
PHP backdoor that receives commands via HTTP cookie, providing remote shell access to compromised web servers with custom command support.

PHP backdoor that receives commands via HTTP cookie, providing remote shell access to compromised web servers with custom command support.

JavaScript-based BurpSuite plugin for web application pentesting, providing custom scanning, exploitation, and analysis modules.

Exploit for CVE-2023-22515 enabling remote code execution on Confluence servers via custom plugin upload after gaining admin access.

Proof-of-concept exploit for CVE-2022-30190 (Follina) enabling remote code execution via Microsoft Support Diagnostic Tools in Office, with reverse…

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

Python exploit script for CVE-2015-6967, enabling authenticated arbitrary file upload in Nibbleblog 4.0.3 with custom payload support.

PoC exploit for CVE-2026-33017: unauthenticated remote code execution in Langflow via malicious Python Custom Component injection, with built-in…

Proof-of-concept RCE exploit for CVE-2025-55182 targeting Next.js apps. Features interactive shell prompt, batch scanning, custom command execution,…

Python-based exploit tool for CVE-2022-22947 (Spring Cloud Gateway SpEL injection). Supports single-target and batch scanning with custom command…

Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion…

Graphical exploit tool for CVE-2017-12615 (Tomcat PUT arbitrary file write) with vulnerability detection, command execution, and custom webshell…

Proof-of-concept exploit for CVE-2022-29464 enabling unrestricted file upload and remote code execution on vulnerable WSO2 products, with a custom…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

React2Shell (CVE-2025-66478): A Python-based Proof of Concept for Critical Remote Code Execution (RCE) in Next.js Server Components. Features an…

Proof-of-concept exploit script for CVE-2024-24919 that scans target URLs via HTTP POST requests, analyzes responses for unauthorized access or data…

Proof-of-concept and advisory for an unauthenticated privilege escalation in a WooCommerce custom registration plugin, including root cause analysis,…

PoC exploit for CVE-2025-13486, an unauthenticated RCE in the Advanced Custom Fields: Extended WordPress plugin. Verifies vulnerable targets and…

Generate malicious JPEG payloads exploiting ExifTool CVE-2021-22204 for arbitrary code execution, with custom commands or reverse shell support.