
x200-cve-2026-43499
Exploit tool targeting CVE-2026-43499 with automated payload delivery and vulnerability verification for penetration testing engagements.

Exploit tool targeting CVE-2026-43499 with automated payload delivery and vulnerability verification for penetration testing engagements.

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Cisco ASA Software and ASDM Security Research

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin…

WordPress All-in-One Exploit Framework — detector, scanner, enumerator, exploit, escalation. 10 CVEs from the 2026-08 wave incl. CVE-2026-63030…

Liferay XSL - Command Execution (Metasploit)


Metasploit modules in testing

Know a plugin has a php object exploit but need to find which lib to use?

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.

Decrypted content of eqgrp-auction-file.tar.xz

A list of custom Metasploit modules you can use for penetration testing.

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

That repository contains my updates to the well know java deserialization exploitation tool ysoserial.

Exploitation toolkit for RichFaces

Remote code execution for Grandstream GXV3175 VOIP phone.