
CVE-2020-5902
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface…

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface…

Proof-of-concept demonstrating argument injection leading to OS command injection in the CAI framework's find_file utility, enabling arbitrary…

Command-line utility to check if a host is vulnerable to CVE-2019-19781 (Citrix ADC/NetScaler). Scans a single host and reports vulnerability status…

Post-exploitation utility that scans kernel/OS version and configuration to suggest applicable local privilege escalation exploits.

Proof-of-concept exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in Polkit's pkexec utility affecting most Linux…

Python utility that reads accessible gMSA password blobs from Active Directory and extracts plaintext passwords for use in security audits and red…

Proof-of-concept exploit for CVE-2021-4034, a local privilege escalation vulnerability in polkit's pkexec utility, enabling unprivileged users to…

😱 Python library and utility for CVE-2014-6271 (aka. "shellshock")

Steganography brute-force utility to uncover hidden data inside files

Penetration testing utility and antivirus assessment tool.

A cross-platform python based utility for information gathering and penetration testing automation!

A PowerShell based utility for the creation of malicious Office macro documents.

RunasCs - Csharp and open version of windows builtin runas.exe

Group Policy Objects manipulation and exploitation framework

Brosec - An interactive reference tool to help security professionals utilize useful payloads and commands.

Passive URL discovery tool that collects domain-associated URLs from multiple public sources via command-line, supporting stdin/stdout and JSONL…

The perfect butler for pentesters, bug-bounty hunters and security researchers

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…