
MoveIT-CVE-2023-34362-RCE
Ruby-based exploit for CVE-2023-34362 targeting MOVEit Transfer. Automates unauthenticated RCE, creates sysadmin accounts, and deploys a remote shell…

Ruby-based exploit for CVE-2023-34362 targeting MOVEit Transfer. Automates unauthenticated RCE, creates sysadmin accounts, and deploys a remote shell…

CVE-2021-42559: Command Injection via Configurations in MITRE Caldera

CVE-2022-26809-RCE

Python exploit script for CVE-2022-26134, a pre-authentication remote code execution vulnerability in Atlassian Confluence via OGNL injection.…

Atlassian's Confluence Server and Data Center editions (Vulnerable Version > 7.18.1)

Proof-of-concept exploit for CVE-2024-3400, a critical OS command injection vulnerability in GlobalProtect Gateway, enabling remote code execution…

exploit of the Shellshock vulnerability

Chain CVE-2019-11408 – XSS in operator panel and CVE-2019-11409 – Command injection in operator panel.

Shell script exploiting CVE-2024-10914 for remote OS command injection in D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L devices via cgi_user_add.

Python exploit for CVE-2022-46196 targeting unauthenticated command injection in Cacti <=1.2.22. Automates version detection and reverse shell…

This is a script written in Python that allows the exploitation of the Zoneminder's security flaw described in CVE-2023-26035.


PoC for Covenant C2 RCE

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

Self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Plugin-based, multi-provider LLM support with local…

AI-native penetration testing IDE where operators and an AI agent share browser, terminals, traffic capture, shells, asset graph, tasks, and evidence…

AI-powered MCP server for Flipper Zero. Control SubGHz, NFC, RFID, IR, BLE, GPIO, and more over WiFi using Claude or any MCP client.
