
CVE-2026-3228
Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

The Browser Exploitation Framework Project

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938…

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Red team automation framework built on Cobalt Strike, integrating exploit modules, post-exploitation tools, and lateral movement capabilities for…

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

Original proof-of-concept exploits for React2Shell (CVE-2025-55182), demonstrating remote code execution in Next.js applications via Webpack chunk…

Bypass firewall for traffic forwarding using webshell

Aggressor Script, Kits, Malleable C2 Profiles, External C2 and so on


Exploits by 1N3 @CrowdShield @xer0dayz @XeroSecurity

Public repository for improvements to the EXTRABACON exploit

CVE-2018-8174 - VBScript memory corruption exploit.

[ProxyLogon] CVE-2021-26855 & CVE-2021-27065 Fixed RawIdentity Bug Exploit. [ProxyOracle] CVE-2021-31195 & CVE-2021-31196 Exploit Chains.…

Python SQL injection framework