
PHP-CGI-INTERNAL-RCE
Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

CVE-2025-29927: Next.js Middleware Exploit

Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

Automation for internal Windows Penetrationtest / AD-Security

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

Agent-server HTTP+TCP tunneling tool for exposing multiple internal services to external networks. Supports multi-level pivoting and SOCKS proxy…

automato should help with automating some of the user-focused enumeration tasks during an internal penetration test.

Security awareness training tool for authorized phishing simulations and internal IT audits

DLL-injectable internal game cheat for Plutonium BO2 zombies

Proof-of-concept exploit for CVE-2022-46364, an Apache CXF SSRF vulnerability enabling arbitrary file reads and internal network probing via crafted…

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Script to exploit CVE-2018-1042 in order to do internal port scans.

PoC for CVE-2024-21626: runc leaks an internal fd referencing the host CWD before pivot_root, enabling container escape by setting process.cwd to…

Technical audit of Kioptrix Level 1. Focus: Samba 2.2.1a exploitation (CVE-2003-0201), manual enumeration, and internal infrastructure hardening.

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Just proof of concept for Cisco CVE-2020-3452. Using external or internal file base.

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…