#1Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.
Kitploit recommended

Exploitation of CVE-2026-24061

Offensive security research hub aggregating original vulnerability advisories, CVE proof-of-concept exploits, conference talks, and internal tooling…

Apache Tomcat Remote Code Execution on Windows

full exploit of pwnfest2016, slide and full text of syscan2017

Proof-of-concept exploit for CVE-2023-21752, an arbitrary file delete vulnerability in Windows Backup service, with two variants including privilege…

Automated penetration testing tool using Cyber Attack Techniques Scoring (CATS) to select and execute optimal attack scenarios via Metasploit, Nmap,…

A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

Validates leaked API tokens and keys using customizable JSON-based signature checks. Designed for pentesters and bug hunters to determine the impact…

:bug: A multi threads web application source leak scanner

Mobile application testing toolkit

Deserialization payload generator for a variety of .NET formatters

A code demonstrating CVE-2018-0886

SQL Server Reporting Services(CVE-2020-0618)中的RCE

Parsero | Robots.txt audit tool

A PS5 hypervisor exploit for 1.xx-2xx firmwares.

n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

Proof-of-concept exploit for CVE-2024-30088, a Windows kernel TOCTOU vulnerability in AuthzBasepCopyoutInternalSecurityAttributes enabling arbitrary…

Python exploit for Jenkins CVE-2024-23897: arbitrary file read via CLI args4j parsing, enabling RCE. Scans hosts and extracts sensitive files from…