
cve-2021-45232-exp
Exploit for CVE-2021-45232 targeting Apache APISIX Dashboard remote code execution vulnerability. Provides proof-of-concept for security testing and…

Exploit for CVE-2021-45232 targeting Apache APISIX Dashboard remote code execution vulnerability. Provides proof-of-concept for security testing and…

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

F5 BIG-IP RCE exploitation (CVE-2022-1388)

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Whitepaper introducing Error-Based and Boolean Error-Based Blind techniques for SSTI and Code Injection, with universal payloads for six programming…

ZIP File Raider - Burp Extension for ZIP File Payload Testing

SpringBoot_Actuator_RCE

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Repo for proof of concept exploits and tools.

A collaborative web exploitation framework.

A collection of useful resources for hacking WordPress and it's plugins and themes

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…

GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's injectable…

Proof-of-concept exploit for Adobe Reader type confusion leading to heap overflow, with detailed root-cause analysis and detection guidance.

CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.