
CVE-2024-46507
build-script for CVE-2024-46507 and CVE-2024-46508

build-script for CVE-2024-46507 and CVE-2024-46508

Proof-of-concept tool that chains DNS injection, NTLM relay, and RPC-based coercion to test authentication relay paths in Windows Active Directory…

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an…

Palo Alto RCE Vuln

React2Shell Exploitation Tool (CVE-2025-55182)

Python-based exploit tool for CVE-2025-25257 in FortiWeb. Automates SQL injection detection, webshell upload, and remote command execution on…

CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.

Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal +…

A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells,…

Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability

Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔…

Suite for reverse shell handling geared toward working within the native shell

PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)

CVE-2025-64155-hunter

Pyrescom Termod proof-of-concept code for CVE-2020-23160, CVE-2020-23161 and CVE-2020-23162

Python exploit for Cacti RCE (CVE-2024-29895) via command injection in cmd_realtime.php. Includes reconnaissance dorks for Google, Shodan, and FOFA.

Proof-of-concept exploit for CVE-2024-3400, a command injection in Palo Alto GlobalProtect. Scans targets, triggers RCE, and retrieves configuration…

MeshDeck port for Arch Linux ARM - Wilson