
CVE-2026-6815
Authenticated path traversal and arbitrary file write PoC exploit for Casdoor <3.54.1, enabling RCE via SSH key injection, web shell upload, or…

Authenticated path traversal and arbitrary file write PoC exploit for Casdoor <3.54.1, enabling RCE via SSH key injection, web shell upload, or…

Proof-of-concept exploit for time-based blind SQL injection in Commend VoIPRec G8-VOIPREC device, targeting the vulnerable Code parameter for…

Automated Mass Exploiter

Python-based proof-of-concept exploit for CVE-2025-5840 targeting file upload vulnerabilities in database management systems, enabling remote command…

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

Blind SQL injection proof-of-concept exploit for RuoYi v4.7.9, bypassing CVE-2024-42900 filter to dump databases via authenticated boolean-based…

Metabase postgres (org.h2.Driver) RCE without INIT

OWASP Mth3l3m3nt Framework is a penetration testing aiding tool and exploitation framework. It fosters a principle of attack the web using the web as…

Gives you one-liners that aids in penetration testing operations, privilege escalation and more

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

CVE-2021-27928-POC