
malicious-pdf
Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.


PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

An enhanced proof-of-concept exploit for CVE-2025-52691 (SmarterMail Arbitrary File Upload RCE) with APT-level features like stealth obfuscation,…

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)


PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp. Démonstration complète incluant : création de payloads, scénarios…


Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

ES File Explorer Open Port Vulnerability - CVE-2019-6447

Content hijacking proof-of-concept using Flash, PDF and Silverlight

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications