
XSScope
XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.

Efficient and advanced man in the middle framework

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

Advanced AI-Powered Exploitation Framework | CVE-2025-4664 & CVE-2025-2783 & CVE-2025-2857 & CVE-2025-30397 |

A PoC for CVE-2023-46604 written as part of SPS class for the Advanced Cyber Security master's at UPB.

Spring has Confirmed the RCE in Spring Framework. The team has just published the statement along with the mitigation guides for the issue. Now, this…

Proof of Concept (PoC) URL generator for a reflected XSS vulnerability in the Advanced Custom Fields WordPress plugin.

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the…

CVE-2025-64328 FreePBX Authenticated Command Injection in the framework module.

CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

Use RedxploitHQ to create a new Admin user into redwoodhq and get all the functions on the framework

Advanced Custom Fields Extended (ACFE) WordPress Plugin Exploit RCE - Admin Creation

POC for CVE-2025-13486

Exploit for CVE-2022-22965 (Spring4Shell) targeting Spring Framework versions vulnerable to remote code execution via classLoader manipulation.

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Python-based proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) targeting Java Spring Core RCE on Apache Tomcat. Uploads a JSP webshell with…