
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

A Python script to exploit CVE-2022-36446 Software Package Updates RCE (Authenticated) on Webmin < 1.997.

Altenergy Power System Control Software set_timezone RCE Vulnerability (CVE-2023-28343)

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

Control Web Panel <= 0.9.8.1208 (admin/index.php) OS Command Injection Vulnerability • Software Link:

PoC for CVE-2025-20265 Cisco Secure FMC Software RADIUS Remote Code Execution Vulnerability

CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect

Exploit script for Pre-Auth RCE in Metabase (CVE-2023-38646)

CVE-2024-3400 PAN-OS: OS Command Injection Vulnerability in GlobalProtect

CVE-2022-36446 - Webmin 1.996 Remote Code Execution

CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

This repository details CVE-2020-6650, a vulnerability I discovered within Eaton's UPS Companion. All users should upgrade to v1.06 immediately or…

CVE-2021-3060

Remote Code Execution at Rittal

Exploit for CVE-2022-23935, a command injection vulnerability in Exiftool versions prior to 12.38, allowing arbitrary command execution via crafted…

Scripts for communication with Bunitu Trojan C&Cs