
CVE-2024-23897
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a…

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a…

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

Real-world attack analysis of CVE-2025-55182 (React2Shell) - React Server Components RCE vulnerability

Deserialization payload generator for a variety of .NET formatters

PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause…

Automated RCE exploit for Joomla JCE (CVE-2026-48907) with interactive shell, batch command execution, file download, and proxy support for…

Microsoft Windows 'HTTP.sys' - Remote Code Execution

Testing TLS/SSL encryption anywhere on any port

detect technologies with wappalyzer alternative

Python exploit for CVE-2026-87902, a WordPress Core LFI-to-RCE chain. Fingerprints versions, writes a PHP shell via pearcmd, and provides command…

Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF…

Passive URL discovery tool that collects domain-associated URLs from multiple public sources via command-line, supporting stdin/stdout and JSONL…

Recursively spider webpages to discover all URLs by following links, parsing sitemaps, and robots.txt files. Ideal for security reconnaissance and…

Pulse Secure VPN mitm Research - CVE-2020-8241, CVE-2020-8239

Self-hosted SSRF redirect, payload, callback, and DNS workbench

Exploit framework for CVE-2026-82222, an unauthenticated RCE in GiveWP WordPress plugin. Supports mass scanning, auto-detection, multi-threading,…

Bash PoC for CVE-2024-32002 that exploits Git clone with malicious submodules and symlinks to execute arbitrary commands on Windows and macOS.

TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution.