
CVE-2024-6387
PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)

Go-based scanner that detects SharePoint CVE-2025-53770 RCE vulnerability by injecting a harmless marker into the ToolBox widget and verifying its…

Python 3 checker and exploit helper for CVE-2026-19658, a WordPress Give Tributes PHP object injection flaw, with FOFA target discovery and legacy…

Automated exploit toolkit and detection template for CVE-2024-21546, an unauthenticated RCE in UniSharp Laravel Filemanager, with WAF evasion and…

Payload Generation Framework

A DNS rebinding attack framework.

Notes about attacking Jenkins servers

Modern tactical exploitation toolkit.

Intranet penetration tools

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

Python codes of my blog.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

how detect CVE-2020-2551 poc exploit python Weblogic RCE with IIOP

abusing windows toast notifications for fun and user manipulation

hacklib - pentesting, port scanning, and logging in anywhere with Python

Active Directory time discovery protocols for red teams. Stealthy extraction via Kerberos, SMB, NTLM, and CLDAP.

A care package of useful bofs for red team engagments

Example PoC Code for CVE-2017-5638 | Apache Struts Exploit