
nemesis
A command-line network packet crafting and injection utility

A command-line network packet crafting and injection utility

Modular GCP attack toolkit for offensive research, enabling reconnaissance, authentication manipulation, and exploitation of cloud functions,…

caplets and proxy modules.

Research tools for MouseJack vulnerabilities in nRF24L01 wireless devices, including device discovery, packet sniffing, network mapping, and firmware…

PoC exploit and NSE scanner for CVE-2021-21985, a vCenter Server RCE vulnerability in the vSAN Health Check plugin, with manual exploitation steps…

A framework for BREACH and other compression-based crypto attacks

Proof-of-concept exploit for CVE-2025-5419, demonstrating a critical vulnerability with a JavaScript-based implementation for security testing and…

Proof-of-concept exploit for CVE-2022-22963 (Spring Cloud Function SpEL RCE). Scans URLs, executes commands, and identifies vulnerable targets.

Proof-of-concept exploit for CVE-2023-36845 enabling unauthenticated remote code execution on Juniper SRX firewalls and EX switches via PHP…

Python exploit script for CVE-2021-26855 (Microsoft Exchange Server SSRF) with integrated ZoomEye dork for mass scanning and detection of vulnerable…

Go-based scanner that detects SharePoint CVE-2025-53770 RCE vulnerability by injecting a harmless marker into the ToolBox widget and verifying its…

Python-based exploit and detection script for CVE-2021-21972 (VMware vCenter unauthorized RCE), using Zoomeye dork for host discovery and pocsuite3…

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support

Identifying and Mitigating the CVE-2020–0796 flaw in the fly

These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)

VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.

Proof-of-concept exploit for CVE-2023-27350 targeting authentication bypass in PaperCut MF/NG print management software. Includes Shodan dorks for…