
React2Shell
Scans and exploits two React/Next.js RCE vulnerabilities (CVE-2025-55182, CVE-2025-66478) with command execution, interactive shell, and bulk target…

Scans and exploits two React/Next.js RCE vulnerabilities (CVE-2025-55182, CVE-2025-66478) with command execution, interactive shell, and bulk target…

Proof-of-concept exploit for CVE-2022-41080 (OWASSRF) enabling remote code execution through Microsoft Exchange Outlook Web Access, bypassing…

Scanning tool to test for SaltStack vulnerabilities CVE-2020-11651 & CVE-2020-11652.

A simple bash script that exploits CVE-2021-22205 against vulnerable instances of gitlab

Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in…

Professional PoC for CVE-2025-59536 and related CVEs. Demonstrates an MCP Tool Confirmation Prompt Misrepresentation in Anthropic Claude_Code leading…

Automated mass exploitation tool for CVE-2019-16920 command injection vulnerability in multiple D-Link routers, enabling unauthenticated remote code…

Proof-of-concept exploit for CVE-2025-66478, demonstrating remote code execution in Next.js via crafted multipart requests with prototype pollution.

Python exploit for CVE-2022-1388, an unauthenticated remote command execution vulnerability in F5 BIG-IP iControl REST. Supports single commands and…

Unauthenticated remote command execution exploit for Progress Kemp LoadMaster CVE-2024-1212. Supports proxy interception and output logging for…

Proof-of-concept exploit for CVE-2017-1000117, demonstrating remote code execution via malicious Git submodule URLs using SSH ProxyCommand injection.

Python proof-of-concept for authenticated command injection in Hikvision wireless APs, enabling remote code execution testing with customizable…

Authenticated Command Injection Tool (CVE-2022-31898) - HACKCONRD 2026.

CVE-2025-64155

Detailed technical analysis and proof-of-concept exploit for CVE-2023-20209, a post-authentication remote code execution vulnerability in Cisco…

Interactive RCE Web Shell (CVE-2025-55182) BY Golden-Security

Go-based exploit for CVE-2024-3400, enabling unauthenticated remote code execution on PAN-OS firewalls via command injection in GlobalProtect.…

CVE-2023-46747-RCE PoC