
watchTowr-vs-FortiSIEM-CVE-2025-25256
Detection artifact generator for FortiSIEM CVE-2025-25256 unauthenticated remote command execution vulnerability. Sends crafted packets to verify…

Detection artifact generator for FortiSIEM CVE-2025-25256 unauthenticated remote command execution vulnerability. Sends crafted packets to verify…

Remote code execution exploit for Drupal CVE-2018-7600 (Drupalgeddon2) with command injection via HTTP requests.

提供批量扫描URL以及执行命令功能。Workspace ONE Access 模板注入漏洞,可执行任意代码

Proof-of-concept exploit for CVE-2024-8190, an authenticated command injection vulnerability in Ivanti Cloud Service Appliance, enabling remote…


CVE-2025-57819 -> rce

Exploit for CVE-2022-25765 command injection in pdfkit < 0.8.6

CVE-2022-31245: RCE and domain admin privilege escalation for Mailcow

Python exploit for CVE-2022-22947 (Spring Cloud Gateway RCE) with command execution, reverse shell, and vulnerability detection via Actuator API SpEL…

Python-based exploit for CVE-2024-10914 targeting command injection in D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L NAS devices.

PoC for Unauthenticated RCE in FortiSandbox via CVE-2026-39808

Mass exploitation tool for CVE-2024-4358, executing commands on multiple web targets concurrently with threading support.

PoC for CVE-2025-4660 demonstrating exploitation of the Forescout SecureConnector on Windows

The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.

Havoc SSRF to RCE

Tool for CVE-2022-1388

Exploit script for CVE-2024-3400, a command injection in PAN-OS GlobalProtect, allowing unauthenticated remote code execution with root privileges.…

Proof-of-concept exploit for CVE-2024-29973, a command injection vulnerability in Zyxel NAS devices. Executes arbitrary OS commands via a crafted…