
Http-Asynchronous-Reverse-Shell
[POC] Asynchronous reverse shell using the HTTP protocol.

[POC] Asynchronous reverse shell using the HTTP protocol.

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

Exploit for Fastjson RCE (CVE-2026-16723) targeting versions 1.2.68 to 1.2.83. Generates JAR and JSON payloads, hosts HTTP server, and establishes…

Rejetto http File Server 2.3.x (Reverse shell)


#F5-BIG-IP-CVE-2023-46747-Exploit – Unauthenticated RCE Python exploit & Nuclei template by Raguraman ✓ Automated TCP reverse shell (LHOST/LPORT)…

Burp Suite/antsword - Interactive shell (HTTP hijack + POST + AES-256-CBC/BASE64)

Python-based forward shell tool that creates a TTY-like interactive shell over HTTP using named pipes, enabling command execution on firewalled…

Stealthy standalone PHP web shell with HTTP header-based authentication, exec function switching, and undetectable design for remote command…

CVE-2026-48907 is a CVSS 10.0 pre-auth RCE in Joomla Content Editor affecting all versions ≤ 2.9.99.4. The Grayxploit team breaks down the 3-weakness…

Script to automate PUT HTTP method exploitation to get shell

CVE-2025-24813-POC JSP Web Shell Uploader

Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized…

CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated…

CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920