
Homework-of-Python
Collection of Python scripts for vulnerability exploitation, credential attacks, and post-exploitation on web applications, Exchange, vCenter, and…

Collection of Python scripts for vulnerability exploitation, credential attacks, and post-exploitation on web applications, Exchange, vCenter, and…

abusing windows toast notifications for fun and user manipulation

hacklib - pentesting, port scanning, and logging in anywhere with Python

Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.

A care package of useful bofs for red team engagments

Python PoC exploit for Apache Struts2 CVE-2017-5638 with corrected Content-Type header formatting, logging, and automated target scanning via DORK…

Proof-of-concept exploit for CVE-2026-57827: unauthenticated file upload RCE in RSFiles! Joomla component. Includes mass scanning and automated shell…

Exploit for ActiveMQ deserialization RCE (CVE-2015-5254) using jmet to send crafted serialized payloads via OpenWire port 61616, with command…

Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.

Work in Progress. RAT written in C++ using wxWidgets

Authentication Bypass PoC for CVE-2025-2825 – Exploiting CrushFTP 10.x

Exploit for CVE-2026-48908 in Joomla SP Page Builder, enabling unauthenticated arbitrary file upload and remote code execution with mass scanning and…

Collection of proof-of-concept exploits and payloads for CVE-2019-0708 (BlueKeep) vulnerability, targeting RDP remote code execution for penetration…

Proof-of-concept exploit for CraftCMS remote code execution (CVE-2025-32432), featuring automated asset ID discovery, session injection, and…

Disclosure and PoCs for CVE-2025-68413 and CVE-2025-68414

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

CVE-2024-23897: Jenkins Arbitrary File Read Lead to RCE

A testing tool for CobaltStrike-RCE:CVE-2022-39197; Weblogic-RCE:CVE-2023-21839; MinIO:CVE-2023-28432