
struts2-tool
Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool

Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Cloud dead-drop C2 framework — RSA-4096 + AES-256-GCM, 5 cloud providers, Rust-only agents, P2P mesh, persistence engine, credential harvesting

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

Exploitation toolkit for CVE-2026-22812 (OpenCode unauthenticated RCE) providing interactive shell, arbitrary command execution, file…

Proof-of-concept exploit for CVE-2026-24061 providing an interactive remote shell session with configurable timeouts for reliable exploitation.

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

Proof-of-concept demonstrating a command injection vulnerability in MS-Agent Shell tool, enabling arbitrary command execution and reverse shell via…

Proof-of-concept exploit for CVE-2026-23744, targeting /api/mcp/connect to achieve remote command execution on Linux systems via reverse shell.

Java GUI tool for exploiting CVE-2026-21962, an unauthenticated RCE in Oracle WebLogic Proxy Plug-In, enabling multi-target command execution via…

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

All-in-one exploit tool for CVE-2026-27966, a critical RCE in Langflow. Features mass scanning, auto-detection, payload execution, interactive shell,…

cPanelSniper STABLE - CVE-2026-41940 optimized for 10M+ targets

Python exploit tool for OpenCode RCE (CVE-2026-22812) providing command execution, file read/write/upload/download, and interactive shell for…

Ruby-based exploit for CVE-2026-24061 that executes arbitrary commands on remote targets, supporting multi-threaded scanning and command injection…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

CLI and interactive console for listing, browsing, and extracting files from VM disk images (VHDX, VMDK, EBS snapshots, raw disks) for red-team…