
CVE-2017-18044-Exploit
Commvault-CVE-2017-18044

Commvault-CVE-2017-18044

React2Shell - CVE-2025-66478 RCE Exploit

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

A collection of selenium tests that might aid it takeover of a selenium node

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

CVE-2018-16858 exploit implementation

Crestron AirMedia AM-100 RCE (CVE-2016-5640) Metasploit Module

Repository for CVE-2020-15568 Metasploit module

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

Extending of metasploit-framework

POC for CVE-2025-24054

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

Project that brings together several pentest tools

Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration,…

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

CVE-2023-33538 - TP-Link Command Injection Ruby module for Metasploit Framework

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that…