
CVE-2026-38360
Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

Pentest Tools Framework is a database of exploits, Scanners and tools for penetration testing. Pentest is a powerful framework includes a lot of…

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Active deception tool that transparently migrates attackers from real targets to honeypots during exploitation and post-exploitation, supporting…

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability

Casper@shell:~# is an enhanced, more user-friendly version of p0wny shell with many new features.


Unauthenticated path traversal exploit for CVE-2026-104286 in FortiMail, writing arbitrary files via crafted HTTP/HTTPS requests for red team…

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…

A native backdoor module for Microsoft IIS (Internet Information Services)

Web Backdoor Cookie Script-Kit


Stealthy IIS backdoor using hidden ISAPI filter for persistent remote access, data exfiltration, and on-the-fly exploit injection via custom HTTP…

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole…

Web application backdoor builder

Proof-of-concept for a reflected XSS vulnerability in CheckMK Management Web Console (versions 1.5.0 to 1.6.0), enabling session theft or backdoor…

Web-Security-Learning

This is POC for CVE-2024-2667 (InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload)