
cve2025-20265
Safe Python script to detect Cisco FMC instances potentially vulnerable to CVE-2025-20265. Uses official FMC API to check version, supports…

Safe Python script to detect Cisco FMC instances potentially vulnerable to CVE-2025-20265. Uses official FMC API to check version, supports…

Python exploit for CVE-2026-89012, a Dolibarr SQL filter denylist bypass that uses a blind-boolean oracle to extract password hashes and API keys via…

Uses Shodan API to pull down C2 servers to run known exploits on them.

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

Python-based directory traversal exploit for CVE-2020-17519 (Apache Flink) with multi-threading, proxy support, and configurable depth for retrieving…

Python exploit for CVE-2024-50395, an authorization bypass in QNAP Media Streaming add-on. Uses crafted User-Agent headers to bypass authentication…

Python exploit for Jenkins CVE-2024-23897: arbitrary file read via CLI args4j parsing, enabling RCE. Scans hosts and extracts sensitive files from…

Python exploit for CVE-2022-36537, an authentication bypass in ZK Framework affecting R1Soft Server Backup Manager, allowing retrieval of web context…

GitLab 12.9.0 Arbitrary File Read

PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

Nuclei-based detection template for CVE-2025-68613, a critical RCE in n8n workflow automation. Uses multi-layered passive fingerprinting to identify…

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

Exploit scanner for CVE-2022-26134 in Atlassian Confluence. Uses Shodan to find vulnerable hosts, then executes commands via the OGNL injection…

PHP CLI script to scan domains for the CVE-2014-0160 (Heartbleed) vulnerability using an external API service.

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

Proof-of-concept exploit for CVE-2022-40881 targeting SolarView Compact devices. Uses fofa query for reconnaissance and payload delivery for…

Proof-of-concept exploit for CVE-2024-56331, demonstrating Local File Inclusion in Uptime Kuma via improper URL handling in the real-browser monitor.…

Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map,…