
CVE-2021-41730
Proof-of-concept exploit for CVE-2021-41730, demonstrating remote command execution in TENDA AC15/AC6 routers via unvalidated formSetIptv()…

Proof-of-concept exploit for CVE-2021-41730, demonstrating remote command execution in TENDA AC15/AC6 routers via unvalidated formSetIptv()…

Exploit for EasyNAS version 1.1.0. The vulnerability exploited is a command injection flaw, which requires authentication.

Python exploit for CVE-2022-46196 targeting unauthenticated command injection in Cacti <=1.2.22. Automates version detection and reverse shell…

GOGS RCE cve-2025-8110 python script that automates the whole attack chain of creating a repository with a symlink file pointing to .git/config and…

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523

HikvisionExploiter is a Python-based utility designed to automate exploitation and directory accessibility checks on Hikvision network cameras…

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

A version of CVE-2017-0213 that I plan to use with an Empire stager

A critical RCE vulnerability has been identified in the Wazuh server due to unsafe deserialization in the wazuh-manager package. This bug affects…

Unauthenticated RCE exploit for GeoServer (CVE-2024-36401) via OGC filter XPath injection. Supports reverse shell and blind command execution with…

Modify version of impacket wmiexec.py, get output(data,response) from registry, don't need SMB connection, also bypassing antivirus-software in…

Veil 3.1.X (Check version info in Veil at runtime)

Database Driven DNS Server with a Web UI

Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)

DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine,…

A WebDAV PROPFIND C2 tool