
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Curated collection of Shodan search filters (dorks) for discovering exposed devices, databases, ICS systems, and web applications. Covers network…

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Exploit tool for CVE-2018-9995 that extracts DVR credentials via HTTP request with cookie bypass, targeting multiple vendor devices for security…

Authenticated command injection exploit for Tenda HG9 routers. Provides interactive remote shell access via Python script for penetration testing and…

Remote buffer overflow exploit for D-Link DIR-619L router (CVE-2024-9570) targeting the formEasySetTimezone function for penetration testing and…

Authenticated remote code execution exploit for NETIS WF2419 routers via command injection in the tracert diagnostic tool. Requires web management…

Proof-of-concept exploit for CVE-2025-29384, a critical stack-based buffer overflow in Tenda AC9 routers. Includes Python and Metasploit modules for…

Unauthenticated OS command injection exploit for Shenzhen Aitemi M300 Wi-Fi Repeater with validator, payload generator, and Metasploit module for…

CVE-2026-54477 disclosure detailing missing security headers (CSP, X-Frame-Options) in Gardyn IoT admin panel enabling clickjacking and XSS, with…

The DGS-1510 Websmart switch series firmware has been found to have security vulneratiblies. The vulnerabilities include unauthenticated command…

Proof-of-concept exploit for CVE-2026-36356: unauthenticated OS command injection in MeiG Smart FORGE_SLT711 GoAhead web server, enabling root-level…

Python exploit for CVE-2021-36260 command injection in Hikvision web servers. Supports safe/unsafe vulnerability verification, remote command…

Exploit for CVE-2018-9995 targeting DVR devices. Sends a crafted Cookie header to retrieve plaintext admin credentials from the web control panel.

Proof-of-concept exploit for a buffer overflow vulnerability (CVE-2024-44596) in Netis N5VN AC1200 routers, causing a denial of service by crashing…

Proof-of-concept for stored XSS vulnerability in Rittal CMC PU III web management interface, enabling persistent client-side script injection before…

Proof-of-concept exploit for CVE-2024-4232 targeting plaintext password storage in Digisol DG-GR1321 routers. Demonstrates extraction of credentials…