
CVE-2025-3248
Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Python proof-of-concept for CVE-2025-11740; triggers the vulnerability to verify exposure and support remediation in authorized security tests.

Proof-of-concept exploit for CVE-2026-72898 in Metabase, with technical reproduction steps and usage guidance for validating the vulnerability during…

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege

LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)


Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

CVE-2014-2630 exploit for xglance-bin

Docker container implementing tests for CVE-2016-2107 - LuckyNegative20


This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…
