
Lfi-Space
Automated Local File Inclusion (LFI) vulnerability scanner with Google Dork search and targeted URL scan modes for web application security testing.

Automated Local File Inclusion (LFI) vulnerability scanner with Google Dork search and targeted URL scan modes for web application security testing.

Repository containing nse script for vulnerability CVE-2022-21907. It is a component (IIS) vulnerability on Windows. It allows remote code execution.…

Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

intentionally vuln web Application Security in django

SQLi scanner to detect SQL vulns

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

CVE-2023-3519 vuln for nuclei scanner

Citrix ADC Vulns

Shattered is a tool and POC for the new CrushedFTP vulns, CVE Exploit Script: CVE-2025-2825 vs CVE-2025-31161

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

A C2 project that controls a self-propagating MS17-010 worm.

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

Scanner for Zyxel products which are potentially vulnerable due to an undocumented user account (CVE-2020-29583)

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

Palo Alto RCE Vuln

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

Python exploit for CVE-2015-1579 targeting WordPress Slider Revolution <= 4.1.4, allowing remote file disclosure. Usage: python3 xpl.py --url=target.