
CVE-2026-25253-research
Proof-of-concept exploit for CVE-2026-25253, demonstrating one-click RCE on OpenClaw via Cross-Site WebSocket Hijacking. Includes attacker server and…

Proof-of-concept exploit for CVE-2026-25253, demonstrating one-click RCE on OpenClaw via Cross-Site WebSocket Hijacking. Includes attacker server and…

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

Authenticated PoC for CVE-2026-0911: tests weak file upload and orphan file behavior in WordPress Hustle plugin's module import endpoint, with…

PoC exploit for CVE-2020-11800, a command injection in Zabbix Server via malicious agent auto-registration, with Python-based payload delivery and…

Proof-of-concept exploit for CVE-2024-54160 demonstrating stored XSS and HTML injection in OpenSearch Reports plugin via malicious iframe payload in…

SSTI vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to use native template syntax to inject a malicious payload into a template,…

A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

增强版WeblogicScan、检测结果更精确、插件化、添加CVE-2019-2618,CVE-2019-2729检测,Python3支持

XSS payloads designed to turn alert(1) into P1

TrevorC2 is a legitimate website (browsable) that tunnels client/server communications for covert command execution.

HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

RCE exploit for dompdf

Chrome V8 n-day exploits that I've written.
