
FortiSandbox-RCE-Exploit-CVE-2026-39808
Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)

Proof-of-concept exploit for CVE-2026-30368, demonstrating authentication bypass in Lightspeed Classroom to control student devices via Ably channel.

Multi-threaded Python scanner for CVE-2022-1388, an F5 BIG-IP remote code execution vulnerability. Supports single URL and batch file input, with…

Proof-of-concept exploit for CVE-2022-26134 in Confluence Server, using OGNL injection to execute commands via crafted HTTP requests.

CVE-2020–7961 Mass exploit for Script Kiddies

Exploit and mass-check script for CVE-2022-1388 targeting F5 BIG-IP iControl REST unauthenticated remote command execution. Supports single host,…

Python-based exploit for CVE-2025-3248 enabling remote code execution on vulnerable Langflow instances. Supports single URL and bulk scanning with…

Proof-of-concept exploit for CVE-2026-41940 targeting cPanel, enabling account enumeration, command execution, and interactive shell access on…

Proof-of-concept scanner for CVE-2025-55182, an unauthenticated RCE in React Server Components. Supports batch scanning, JSON/CSV export, and…

Proof-of-concept exploit for CVE-2022-22954, a VMware Workspace ONE Access and Identity Manager RCE via SSTI. Supports manual, file-based, and…

Python-based exploit for Apache Struts CVE-2017-5638 with single URL and batch scanning modes, vulnerability checking, and Nmap reconnaissance…

PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)

Exploit script for CVE-2022-1388 targeting F5 BIG-IP pre-auth RCE via /mgmt/tm/util/bash endpoint. Includes detection, version scanning, and…

Exploit for CVE-2023-36845, a PHP environment variable manipulation vulnerability in Juniper SRX/EX, enabling unauthenticated remote code execution…

Proof-of-concept exploit for CVE-2024-3400, a command injection in Palo Alto GlobalProtect. Scans targets, triggers RCE, and retrieves configuration…

Python exploit for Cacti RCE (CVE-2024-29895) via command injection in cmd_realtime.php. Includes reconnaissance dorks for Google, Shodan, and FOFA.

Proof-of-concept for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including vulnerable server setup, exploit…