
waybend
Self-hosted SSRF redirect, payload, callback, and DNS workbench

Self-hosted SSRF redirect, payload, callback, and DNS workbench

Python exploit for MS09-050 (CVE-2009-3103) SMBv2 srv2.sys buffer overflow, with vulnerability scanner, arch auto-detection, and x86/x64 reverse…

MCP server packaging a three-tier penetration-testing methodology: attack-surface reconnaissance, source-to-sink static analysis, and live finding…

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

Validates pre-authentication reflected XSS in WordPress, fingerprints vulnerable versions, checks payload reflection and JSONP, and generates…

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

Remote Java classpath enumeration via deserialization

woodpecker-plugins

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 |…

WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering

Generates detection artifacts for CVE-2026-21902 on Juniper Junos Evolved, enabling verification of unauthenticated remote code execution via command…

Self contained htaccess shells and attacks

DNS-Persist is a post-exploitation agent which uses DNS for command and control.

PwnSTAR (Pwn SofT-Ap scRipt) - for all your fake-AP needs!

Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.