
CVE-2022-29464-mass
Mass exploit tool for CVE-2022-29464, a pre-auth RCE in WSO2 Carbon Server, with single-target and batch scanning via file input and search dorks.

Mass exploit tool for CVE-2022-29464, a pre-auth RCE in WSO2 Carbon Server, with single-target and batch scanning via file input and search dorks.

Automated exploit tool for CVE-2021-42237 targeting SiteCore XP. Reads target URLs from a file and leverages DNSLog for out-of-band detection.

Proof Of Concept that exploits PuTTy CVE-2024-31497.

Proof-of-concept exploit for CVE-2025-45955 demonstrating Server-Side Request Forgery (SSRF) in DonWeb Ferozo hosting platform, enabling internal…

Proof-of-concept exploit for CVE-2025-24071, leveraging a crafted ZIP file to trigger SMB authentication relay and capture NTLM hashes via Impacket.

PoC exploit collection for CVE-2018-7600 Drupal RCE with multiple scripts targeting Drupal 7 and 8, including mass exploitation variants.

Golang network scanner with arp discovery and own parser

Leveraging arbitrary file read to RCE on Oracle PeopleSoft

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

Detects and exploits Apache CVE-2021-42013 for remote code execution and local file disclosure via Nmap, Python, and Ruby scripts.

Multi-language exploit and detection scripts for CVE-2021-41773, enabling remote code execution and local file disclosure on vulnerable Apache…

Proof-of-concept exploit for CVE-2021-26855 (ProxyLogon SSRF) enabling file write via Exchange server vulnerability. Demonstrates the SSRF chain for…

Oracle WebLogic CVE-2022-21371

Explore CVE 2023-30845 automatically across multiple subdomains

Global Protec Palo Alto File Write Exploit

CLI scanner for CVE-2006-2842 (PHP include() path truncation) vulnerability. Scans single or multiple URLs to detect this specific web application…