
CVE-2022-29078
Proof-of-concept exploit for CVE-2022-29078 (ejs 3.1.6) enabling remote command execution via a Python script. Accepts a target URL and provides an…

Proof-of-concept exploit for CVE-2022-29078 (ejs 3.1.6) enabling remote command execution via a Python script. Accepts a target URL and provides an…

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

This app is the standard Asp.Net default web app with an old version of the AjaxControlToolkit, put here for those interested in CVE-2015-4670

Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

intentionally vuln web Application Security in django

SQLi scanner to detect SQL vulns

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Citrix ADC Vulns

PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2

Weblogic Vuln POC EXP cve-2020-2551 cve-2020-2555 cve-2020-2883 ,。。。

GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's injectable…

Nuclei templates for drupal vulns... far from perfect

Wordpress 5.8.2 CVE-2022-21661 Vuln enviroment POC exploit

Shattered is a tool and POC for the new CrushedFTP vulns, CVE Exploit Script: CVE-2025-2825 vs CVE-2025-31161

Scanner PoC for CVE-2019-0708 RDP RCE vuln

CVE-2023-3519 vuln for nuclei scanner

cve-2014-0130 rails directory traversal vuln