
CVE-2022-46364-Poc
Python exploit for CVE-2022-46364 (Apache CXF SSRF via MTOM XOP:Include). Sends crafted SOAP requests to exfiltrate internal metadata, credentials,…

Python exploit for CVE-2022-46364 (Apache CXF SSRF via MTOM XOP:Include). Sends crafted SOAP requests to exfiltrate internal metadata, credentials,…

CVE-2021-41773: Path Traversal Zero-Day in Apache HTTP Server Exploited

Unauthenticated RCE exploit and detection scanner for Weaver E-cology, targeting the dubboApi debug endpoint. Includes PoC, Nmap NSE script, and…

To assist in enumerating the webserver behind the webserver SSRF CVE-2023-27163

A comprehensive Python utility to **detect**, **scan in bulk**, and **exploit** the critical authentication bypass vulnerability (CVE-2026-41940) in…

Exploit for CVE-2020-11547: unauthenticated information disclosure in PRTG Network Monitor via crafted HTTP requests to /public/login.htm or…

Identifying all log4j components across on local windows servers. CVE-2021-44228

POC CVE-2025-26318

OpenMetadata_RCE (CVE-2024-28255) Batch scan/exploit

CVE-2023-32315-Openfire-Bypass

Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into…

Automated exploit tool for CVE-2023-32315 authentication bypass vulnerability. Scans single or bulk targets with multiprocessing and automatic login…

Shell script to check Ivanti EPMM (MobileIron Core) instances for CVE-2023-35078 remote unauthenticated API access vulnerability, with Shodan dorks…

Proof-of-concept exploit for CVE-2022-26134 in Confluence Server, using OGNL injection to execute commands via crafted HTTP requests.

Ultrafast CUPS-browsed scanner (CVE-2024-47176)

wp2shell - WordPress RCE & PoC (CVE-2026-63030 + CVE-2026-60137)

Automated scanner and exploit for CVE-2019-2725 (Oracle WebLogic RCE). Reads target IPs from ip.txt, checks for vulnerability, and saves exploitable…