
CVE-2022-42475-POC
Exploit for CVE-2022-42475, a pre-auth RCE in FortiOS SSL VPN. Supports validation, benign verification, and full exploitation with connect-back…

Exploit for CVE-2022-42475, a pre-auth RCE in FortiOS SSL VPN. Supports validation, benign verification, and full exploitation with connect-back…

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

Python script to detect CVE-2024-23113, a format string vulnerability in FortiGate FGFM service on TCP/541, using SSL connection and crafted payload…

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…

Proof-of-concept exploit for CVE-2019-11477, demonstrating a denial-of-service attack against Linux kernel TCP SACK panic via crafted netfilter…

Proof-of-concept exploit for CVE-2020-8289 demonstrating remote code execution as SYSTEM/root via Backblaze backup client's SSL verification bypass…

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

Shodan-based scanner that discovers FortiGate SSL VPN devices and tests them for CVE-2024-21762 vulnerability, displaying organization and country…

Proof-of-concept scanner for Apache HTTP Server path traversal (CVE-2021-41773) with multi-host support, SSL verification toggle, and concurrent…

CVE-2026-39987 for marimo 0.20.4 PoC

Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation…

Exploit script for CVE-2024-24919 targeting Check Point SSL VPN, with Shodan and FOFA search queries for vulnerable devices.

Frida-powered runtime mobile exploration toolkit for assessing iOS and Android app security. Bypass SSL pinning, dump keychains, manipulate heap…

Python script to check for CVE-2024-3400 vulnerability in Palo Alto Networks PAN-OS SSL VPN by probing /ssl-vpn/hipreport.esp and verifying file…

Proof-of-concept exploit for Apple SSL/TLS verification vulnerability (CVE-2014-1266) in iOS and OS X, demonstrating HTTPS interception via a proxy…


Exploit for CVE-2018-13379: unauthenticated path traversal in Fortinet FortiOS SSL VPN portal allowing system file download via crafted HTTP requests.

Proof-of-concept exploit for CVE-2024-24919, an unauthenticated arbitrary file read vulnerability in Check Point SSL VPN appliances. Includes Nuclei…