
CheckHKRCE
CVE-2021-36260

CVE-2021-36260

1vere$k POC on the CVE-2023-20198

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.

Laravel Crypto Killer Mass Scanner (CVE-2024-55555)

Mass exploitation tool for CVE-2022-29464 targeting WSO2 Carbon Server. Automates pre-auth RCE scanning via Shodan/ZoomEye, uploads webshells and…

Docker-based multi-stage attack emulation lab demonstrating CVE-2017-5638 and CVE-2021-41773 exploitation, lateral movement, and Suricata IDS…

This is a Python-based exploit for CVE-2025-49493, which affects Akamai CloudTest versions before 60 2025.06.02 (12988). The vulnerability allows for…

Python-based exploit for CVE-2025-3248 enabling remote code execution on vulnerable Langflow instances. Supports single URL and bulk scanning with…

Exploit for CVE-2026-23980 — Authenticated error-based SQL injection in Apache Superset < 6.0.0 via sqlExpression bypass

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

Simple scanner to detect vulnerable Livewire installations.

A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths…

CVE-2020-14882 detection script

CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool

Python-based exploit for CVE-2024-25600 targeting Bricks Builder WordPress plugin RCE. Automates nonce extraction, payload injection, and arbitrary…

Proof-of-concept exploit for CVE-2024-9465, a time-based SQL injection in Check Point Expedition, with Shodan/FOFA search queries and integration…