
kamene
Network packet and pcap file crafting/sniffing/manipulation/visualization security tool. Originally forked from scapy in 2015 and providing python3…

Network packet and pcap file crafting/sniffing/manipulation/visualization security tool. Originally forked from scapy in 2015 and providing python3…

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

Unauthenticated arbitrary file read exploit for Jenkins CVE-2024-23897, with HTTPS and CSRF-crumb support to bypass hardened instances.

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

Proof-of-concept exploit for CVE-2026-26336, an unauthenticated path traversal in Alfresco Share allowing arbitrary file read within the webapp and…

IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness

Mass scanner for Grafana CVE-2021-43798 unauthorized file read, supporting single targets, hostname lists, and IP ranges with PoC verification.

Unauthenticated directory enumeration PoC for MRCMS V3.1.2, exploiting missing authentication in /admin/file/list.do to disclose server directory…

Detects and exploits Apache CVE-2021-42013 for remote code execution and local file disclosure via Nmap, Python, and Ruby scripts.

Multi-language exploit and detection scripts for CVE-2021-41773, enabling remote code execution and local file disclosure on vulnerable Apache…

Proof-of-concept for CVE-2021-21311, a server-side request forgery in Adminer before 4.7.9, demonstrating SSRF exploitation in PHP database…

Proof-of-concept exploit for Grafana arbitrary file reading vulnerability (CVE-2021-43798) affecting versions 8.0.0 to 8.3.0, demonstrating…

Proof-of-concept exploit for CVE-2024-55457, a directory traversal in MasterSAM Star Gate v11 allowing unauthenticated arbitrary file download via…

Exploit for Jenkins arbitrary file leak (CVE-2024-23897) that reads files from the target server via a crafted request.

Exploit for Grafana directory traversal (CVE-2021-43798) allowing local file read via crafted plugin path. Includes usage instructions and references.

Proof-of-concept exploit for CVE-2025-11371, an unauthenticated Local File Inclusion in Gladinet CentreStack and TrioFox, enabling remote file…