
SecureForce
A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing

A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

Automates the compilation and serving of the PwnKit exploit for CVE-2021-4034, enabling local privilege escalation on vulnerable Linux systems.

Modular phishing framework with CLI for cloning sites, sending templated emails, and launching phishing campaigns via email, SMS, iMessage, and…

Multi-architecture assembler framework that converts assembly source into machine code for Arm, x86, MIPS, PowerPC, RISC-V, and more, with a…

Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.

DNS-only command-and-control framework with Windows agent, payload generation, remote shell execution, shellcode injection, and SOCKS5 proxy support…

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

Mogwai Java Management Extensions (JMX) Exploitation Toolkit

Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed…

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

Exploitation toolkit for RichFaces

All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API…

Sickle - Payload Development Kit

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

MCP Server for Metasploit