
MongoBleed-exploit
MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…
Tools for weaponizing vulnerabilities to gain unauthorized access to systems or data.

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

halo cms plugin 1-request rce from a url, PoC + exploit chain

Proof-of-concept exploit code for CVE-2026-54121, adapted and edited for validating the vulnerability in affected environments.

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

Most advanced XSS scanner.

Exploitation Framework for Embedded Devices

fsociety Hacking Tools Pack – A Penetration Testing Framework

Run iOS apps without actually installing them!

An open-source post-exploitation framework for students, researchers and developers.

A swiss army knife for pentesting networks

open-source jailbreaking tool for many iOS devices