
cve-2021-29442-Nacos-Derby-rce-exp
Nacos Derby命令执行漏洞利用脚本

Nacos Derby命令执行漏洞利用脚本

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

PHP Webshell with handy features

Apache CouchDB 3.2.1 - Remote Code Execution (RCE)

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

Webshell, Virtual Private Server (VPS) and cPanel Database

Offensive MSSQL toolkit written in Python, based off SQLRecon

SQLC2 is a PowerShell script for deploying and managing a command and control system that uses SQL Server as both the control server and the agent.

CVE-2021-27928 MariaDB/MySQL-'wsrep provider' 命令注入漏洞

Database authenticated code execution

Proof-of-concept exploit for CVE-2025-66224 demonstrating remote code execution in OrangeHRM via command injection in the sendmail_path parameter,…

CVE-2026-23631 (DarkReplica) Redis Exploit

POC for CVE-2026-25212

Python exploit script for CVE-2019-9193, enabling remote code execution on vulnerable PostgreSQL databases via authenticated command injection.