
yakit
All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin…

Python exploit for CVE-2026-49083, a privilege escalation vulnerability in the LatePoint Calendar Booking WordPress plugin, enabling unauthorized…

Python exploit for CVE-2026-49083 targeting privilege escalation in the LatePoint Calendar Booking WordPress plugin. Provides automated exploitation…

Adaptix C2 service plugin that drives LitterBox payload analysis from the operator UI.

Metasploit exploit for the CVE-2025-50286.

Multi-engine vulnerability scanner with built-in Nuclei Lite, Afrog, and XRay engines. Features asset discovery via FOFA/Shodan, OOB interaction…

Metasploit module exploiting arbitrary file upload in Greenshift WordPress plugin (CVE-2025-3616) to achieve RCE via MIME spoofing, with…

Vulnerability scanner based on vulners.com search API

Hands-on lab for CVE-2023-6933, a PHP Object Injection vulnerability in Better Search Replace WordPress plugin, with Docker deployment, nuclei…

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

Know a plugin has a php object exploit but need to find which lib to use?

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation

Exploit for CVE-2022-1329, a WordPress Elementor plugin RCE vulnerability, allowing authenticated users to upload and execute arbitrary PHP files via…

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

WordPress Backup Guard Authenticated Remote Code Execution Exploit