
poisontap
Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole…

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)


Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

Escaner de identificacion de vulnerabilidades para CVE-2025-4322


Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

Proof-of-concept for a reflected XSS vulnerability in CheckMK Management Web Console (versions 1.5.0 to 1.6.0), enabling session theft or backdoor…

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability

This is POC for CVE-2024-2667 (InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload)

Web-Security-Learning

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Casper@shell:~# is an enhanced, more user-friendly version of p0wny shell with many new features.

Web application backdoor builder

A native backdoor module for Microsoft IIS (Internet Information Services)

Web Backdoor Cookie Script-Kit

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…