
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

Proof-of-concept exploit for CVE-2026-22003 demonstrating Redis Lua sandbox escape via debug.sethook to execute arbitrary system commands.

PoC exploit for CVE-2026-58048, an authenticated cPanel SQL injection that escalates to MySQL root and supports file-read, webshell, and RCE payloads.

MariaDB 13.0.1-rc RCE lab — priv-esc + heap UAF + JOP chain to system() as uid 999(mysql) on stock Docker image. Found with RAPTOR and…

Curated repository of CVEs with PoCs, articles, and detailed descriptions for vulnerability research and exploitation.

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Proof-of-concept exploit for CVE-2025-57819, demonstrating unauthenticated SQL injection to remote code execution chain in FreePBX, including admin…

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

Toolkit for CVE-2025-55182, also known as React2Shell.

Unauthenticated SQL injection to root RCE exploit for FreePBX CVE-2025-57819, chaining SQLi, cron webshell, and incron fwconsole hook for full…

MSSQL client for SCCM environments, enabling reconnaissance, remote PowerShell execution on managed clients, and extraction of sensitive secrets such…

Professional TryHackMe Simple CTF walkthrough covering enumeration, CMS Made Simple SQL Injection (CVE-2019-9053), credential recovery, SSH access,…

Proof-of-concept exploit for CVE-2026-2005, a heap-based buffer overflow in PostgreSQL pgcrypto enabling arbitrary memory read/write and privilege…