
chuckle
An automated SMB relay exploitation script.

An automated SMB relay exploitation script.

Windows KASLR bypass using prefetch side-channel

Modular WLAN auditing framework for red teams with deauthentication, rogue AP, and WPA handshake capture modules. Features a Metasploit-like CLI for…

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

Three-stage Bluetooth BDADDR extraction, DoS & hijack on Fast Pair devices; unpatched primitives outside CVE-2025-36911 scope (no Ubertooth needed)

CVE-2024-24919 exploit

CVE-2024-52940 - A zero-day vulnerability in AnyDesk's "Allow Direct Connections" feature, discovered and registered by Ebrahim Shafiei (EbraSha),…

Apache (Linux) CVE-2021-41773/2021-42013 Mass Vulnerability Checker

CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)

Passive recon & attack surface mapper — zero requests sent

全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner

MailMasta wordpress plugin Local File Inclusion vulnerability (CVE-2016-10956)

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

Go-based PoC for Ghost CMS Content API SQL injection (CVE-2026-26980). Verifies vulnerability, extracts admin credentials and API secrets, and…

Reflected XSS vulnerability found in Palo Alto GlobalProtect Gateway & Portal. Attackers can inject malicious scripts via crafted requests.

POC for CVE-2019-7616 / ESA-2019-09

Python PoC for CVE-2026-93399, an unauthenticated IDOR in Bookly <= 28.2 that leaks order tokens, exposes appointments, and rolls back bookings.