
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

Unauthenticated remote code execution exploit for WordPress core (CVE-2026-63030 + CVE-2026-60137). Chains REST API batch route confusion with SQL…

Proof-of-concept exploit for CVE-2026-63030: unauthenticated blind SQL injection in WordPress REST batch endpoint leading to remote code execution.…

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…

Authenticated remote code execution PoC for Percona PMM before 3.7, abusing PostgreSQL SUPERUSER privileges via COPY ... TO PROGRAM to execute…

Unauthenticated SQL injection to root RCE exploit for FreePBX CVE-2025-57819, chaining SQLi, cron webshell, and incron fwconsole hook for full…

One-shot exploit for FreePBX unauthenticated SQL injection (CVE-2025-57819) chained to RCE via cron_jobs, with listener and interactive shell.

Offensive MSSQL toolkit written in Python, based off SQLRecon

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Python exploit script for CVE-2019-9193, enabling remote code execution on vulnerable PostgreSQL databases via authenticated command injection.

Black-box penetration test of a Drupal 7 server demonstrating a full kill chain: SQL injection (CVE-2014-3704) to RCE, reverse shell, and privilege…

Proof-of-concept exploit for CVE-2025-66224 demonstrating remote code execution in OrangeHRM via command injection in the sendmail_path parameter,…