
CVE-2020-1938_Ghostcat-PoC
Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…

Automated detection and exploitation toolkit for CVE-2025-55182, a critical RCE in Next.js React Server Components. Features multi-layered…

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

High-fidelity RCE scanner for CVE-2025-55182 affecting Next.js RSC. Supports mass scanning, command execution, and automated recon pipelines. Built…

A buffer overflow vulnerability in the XNU kernel's ICMP error code causes IOS devices to crash (laptops and mobiles).

Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal +…

CVE-2025-24071

Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

SOPlanning 1.52.00 CSRF/SQLi/XSS (CVE-2024-33722, CVE-2024-33724)

Python script that generates a PNG image exploiting CVE-2022-44268 to embed and leak local file paths via ImageMagick metadata parsing.

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

Self-hosted SSRF redirect, payload, callback, and DNS workbench

A lightweight Blind XSS (Cross-Site Scripting) collector and payload server built with Flask

PowerSploit - A PowerShell Post-Exploitation Framework

Collection of pentesting scripts

A python based tool for exploiting and managing Android devices via ADB

The LAZY script will make your life easier, and of course faster.