
r2s
Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…

Offensive tool for exploiting management applications (SolarWinds Orion, McAfee ePO) via non-technical vulnerabilities. Enables client enumeration,…

WordPress wp2shell vulnerability-chain scanner for CVE-2026-63030 and CVE-2026-60137, with active detection, optional PoC, JSON export.

PHP server exploitation tool that creates backdoors, bypasses disabled functions via imap_open, and reads sensitive files like /etc/passwd for…

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

An evil RAT (Remote Administration Tool) for macOS / OS X.

Tool to manipulate and weaponize Office Open XML documents.

An XSS exploitation command-line interface and payload generator.

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

iOS/macOS/Linux Remote Administration Tool

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

BurpSuite plugin for HTTP packet analysis and fuzzing dictionary generation. Extracts parameters, paths, and files from requests, counts frequency,…

Multi-purpose penetration testing toolkit bundling 42+ automated scanners, exploiters, brute-forcers, OSINT gatherers, and payload generators for web…

Proof-of-concept exploit collection targeting CVE-2023-2023, with ready-to-use EXP scripts for vulnerability verification and penetration testing…

Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…