
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

Starkiller is a Frontend for PowerShell Empire.

CVE-2023-26039 - ZoneMinder. Any authenticated user can construct an api command to execute any shell command as the web user.

Proof-of-concept exploit for CVE-2021-45026 targeting Rocket Software Zena. Chains stored XSS to remote code execution via REST API task injection on…

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)

Educational demonstration of CVE-2017-5123 kernel exploit, ICMP-based rootkit command-and-control, and OS command injection vulnerable web…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python…

A webshell framework for penetration testers.

CVE Description

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

Detailed CVE-2025-25706 proof-of-concept demonstrating authenticated remote code execution via command injection in ProApps ping functionality,…

WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

OpenPLC 3 WebServer Authenticated Remote Code Execution.

.NET/PowerShell/VBA Offensive Security Obfuscator