
discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

OSCP-focused toolkit for read-only network, SMB, AD, DNS, web, and database enumeration; privesc scanning, hash identification, and…

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

The perfect butler for pentesters, bug-bounty hunters and security researchers

Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

Realistic APT adversary simulation campaigns with custom C2 frameworks, backdoors, stagers, and bootloaders mirroring state-sponsored TTPs for red…

Proof-of-concept exploit for unauthenticated remote code execution in Blocksy Companion Pro via double-extension file upload bypass.

Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE

Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions

Step-by-step black-box penetration test walkthrough exploiting Shellshock RCE (CVE-2014-6271) via Apache mod_cgi, chained with sudo misconfiguration…

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

Exploit script for Apache HTTP Server 2.4.49/2.4.50 path traversal and remote code execution vulnerabilities (CVE-2021-41773, CVE-2021-42013).…

Automated detection and exploitation toolkit for CVE-2025-55182, a critical RCE in Next.js React Server Components. Features multi-layered…

Mass scanner and exploit tool for CVE-2024-4577, a PHP-CGI argument injection vulnerability, enabling automated detection and exploitation of…

Windows Remote Desktop Services Vulnerability Allows Remote Code Execution

Proof-of-concept exploit for CVE-2020-0688 targeting on-prem Microsoft Exchange. Includes scanning, cookie harvesting, payload generation via…

Exploit for JetBrains TeamCity authentication bypass (CVE-2024-27198) enabling remote code execution, with webshell upload and connection…

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port…