
CVE-2025-55182
Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines.

CVE-2023-23397 C# PoC


Proof-of-concept exploit for CVE-2023-27163, a Server-Side Request Forgery (SSRF) vulnerability in request-baskets up to v1.2.1. Includes automated…

Python script to check for CVE-2024-3400 vulnerability in Palo Alto Networks PAN-OS SSL VPN by probing /ssl-vpn/hipreport.esp and verifying file…

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning…

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

PowerShell script to check if a remote device is patched against CVE-2019-0708 by verifying termdd.sys file version against Microsoft's May 2019…

Fast http dead file finder.

a terminal UI to browse bbot reports

A critical vulnerability has been found in HSC Mailinspector up to version 5.2.18. This vulnerability affects an unknown functionality of the file…

Exploits Apache RocketMQ brokers vulnerable to CVE-2023-33246 remote code execution and checks targets via IP, CIDR, or file input.

Lightweight Python script to check Fortinet SSL VPN instances for CVE-2023-27997 vulnerability, supporting single URL and batch file scanning.

Proof-of-concept script to detect CVE-2024-9466 by checking HTTP responses for a specific debug file path on target URLs.

Nmap NSE script to detect Apache HTTP Server path traversal vulnerability (CVE-2021-41773) by sending crafted requests and analyzing responses for…

Python script to exploit CVE-2021-41773, a path traversal vulnerability in Apache 2.4.49, allowing file disclosure and remote code execution.

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…