
xss2shell
Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

Windows Remote Desktop Services Vulnerability Allows Remote Code Execution

Mass scanner and exploit tool for CVE-2024-4577, a PHP-CGI argument injection vulnerability, enabling automated detection and exploitation of…

Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE

Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

Exploit for JetBrains TeamCity authentication bypass (CVE-2024-27198) enabling remote code execution, with webshell upload and connection…

Automated detection and exploitation toolkit for CVE-2025-55182, a critical RCE in Next.js React Server Components. Features multi-layered…

Cross-platform C2 framework using Notion API for stealthy command execution, port scanning, privilege escalation, file download, and shellcode…