
reverse-shell-generator
Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

XSS payloads designed to turn alert(1) into P1

Quicky serve files over http or https using flask.

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection…

Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

Python PoC exploiting CVE-2024-2044 in pgAdmin 4 (<=8.3) via authenticated path traversal and unsafe pickle deserialization to achieve remote code…