
cve-2025-49844
Proof-of-concept for CVE-2025-49844

Proof-of-concept for CVE-2025-49844

A collection of random small Aggressor snippets that don't warrant their own repo

Remote authentication bypass exploit for GNU inetutils-telnetd (CVE-2026-24061) using CRLF injection to gain instant root shell. Supports single/mass…

Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool

C++ exploit for unauthenticated remote code execution on CUPS via CVE-2024-47176 chain.

CVE-2026-27971 qwik rce

Exploit PoC for CVE-2023-20198

Proof-of-concept exploit for CVE-2024-6387 (regreSSHion) targeting unauthenticated remote code execution in OpenSSH server via signal handler race…

CVE-2025-55182漏洞检测工具

Python exploit for CVE-2025-47812, achieving remote code execution on Wing FTP Server via Lua injection in the login username parameter. Supports…

Proof-of-concept exploit for CVE-2025-56015, a sandbox escape and RCE in GenieACS. Automates malicious provision creation, preset mapping, and…

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

JBoss Autopwn as featured at BlackHat Europe 2010 - this version incorporates CVE-2010-0738 the JBoss authentication bypass VERB manipulation…

tac_plus Pre-Auth Remote Command Execution Vulnerability (CVE-2023-45239 & CVE-2023-48643)

Proof-of-concept for OS command injection in Curo UC300 IP phone admin panel, demonstrating arbitrary command execution via the IP Addr parameter.

Go-based vulnerability scanner for detecting CVE-2023-20198 in Cisco IOS XE devices. Tests SOAP/XML interfaces (WSMA) for remote code execution with…

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

CVE-2024-32113 & CVE-2024-38856