
cve-2026-45033-class
CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.

CVE-2026-45033 PoC for Claude Code, not Github Copilot. Worked for Haiku 4.5.

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

Manual, non-Metasploit authenticated Remote Code Execution (RCE) exploit via the browser URL bar for Webmin 1.580 (CVE-2012-2982)

PoC, Hunting React2Shell about CVE-2025-55182

Generates millions of keyword-based password mutations in seconds.


Uses ChatGPT API, Bard API, and Llama2, Python-Nmap, DNS Recon, PCAP and JWT recon modules and uses the GPT3 model to create vulnerability reports…

SSH banner-based vulnerability scanner for CVE-2024-6387 detection with multithreaded scanning, progress bar, and color-coded output for rapid…

Reflected XSS exploit PoC for GLPI (CVE-2024-27914) targeting unauthenticated debug mode. Provides a malicious link to trigger XSS in administrator's…

A vulnerability was found in PHPgurukul visitor management system 1.0. it has been rated as problemic. Affected by the issue is some unknown…

Python script to scan websites for CVE-2023-6895 vulnerability. Sends crafted requests, checks responses, and logs exploitable URLs with progress bar…

Proof-of-concept exploit for a Blind Server-Side Request Forgery (SSRF) vulnerability in Bar Assistant < 3.2.0, enabling authenticated attackers to…

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…

A CVE-2021-22205 Gitlab RCE POC written in Golang

Macally WIFISD2

barq: The AWS Cloud Post Exploitation framework!

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service