
WordPressMassExploiter
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

Proof-of-concept exploit for CVE-2024-9465, a time-based SQL injection in Check Point Expedition, with Shodan/FOFA search queries and integration…

Exploit for CVE-2026-23980 — Authenticated error-based SQL injection in Apache Superset < 6.0.0 via sqlExpression bypass

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

Simple scanner to detect vulnerable Livewire installations.

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

complex webshell manager, quasi-http botnet.

Kyocera cred dumper based on CVE-2022-1026

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

Docker-based multi-stage attack emulation lab demonstrating CVE-2017-5638 and CVE-2021-41773 exploitation, lateral movement, and Suricata IDS…

Weblogic SearchPublicRegistries SSRF(CVE-2014-4210) Exploit Script based on Python3

This is a Python-based exploit for CVE-2025-49493, which affects Akamai CloudTest versions before 60 2025.06.02 (12988). The vulnerability allows for…

Reflected XSS vulnerability found in Palo Alto GlobalProtect Gateway & Portal. Attackers can inject malicious scripts via crafted requests.

Python-based exploit for CVE-2024-25600 targeting Bricks Builder WordPress plugin RCE. Automates nonce extraction, payload injection, and arbitrary…

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths…

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.