
POC_CVE-2026-41940
Proof-of-concept exploit for CVE-2026-41940 targeting cPanel, enabling account enumeration, command execution, and interactive shell access on…

Proof-of-concept exploit for CVE-2026-41940 targeting cPanel, enabling account enumeration, command execution, and interactive shell access on…

IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness

Mass scanner for Grafana CVE-2021-43798 unauthorized file read, supporting single targets, hostname lists, and IP ranges with PoC verification.

Python script to exploit CVE-2021-41773, a path traversal vulnerability in Apache 2.4.49, allowing file disclosure and remote code execution.

Detects and exploits Apache CVE-2021-42013 for remote code execution and local file disclosure via Nmap, Python, and Ruby scripts.

Multi-language exploit and detection scripts for CVE-2021-41773, enabling remote code execution and local file disclosure on vulnerable Apache…

Proof-of-concept exploit for CVE-2026-41551, a path traversal vulnerability in Siemens ROS# file_server, demonstrating remote file read via crafted…

Python tool to check and exploit CVE-2026-22812 in OpenCode, supporting command execution, file read, and multi-target scanning on ports 4095-4100.

An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines.

Make URL path combinations using a wordlist

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

Cobalt Strike BOF for live Windows enumeration of open file handles, revealing which process has locked a target file on disk during…

Subdomain takeover vulnerability checker

👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe…

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

A nice web-crawler written in Bash that will look for login pages/admin-panels for you on any given website.