
Offensive-lab-2
Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the…

Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

Apache HTTP Server 2.4.49, 2.4.50 - Path Traversal & RCE

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

PoC exploit collection for CVE-2018-7600 Drupal RCE with multiple scripts targeting Drupal 7 and 8, including mass exploitation variants.

The perfect butler for pentesters, bug-bounty hunters and security researchers

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

spring框架RCE漏洞 CVE-2022-22965

Apache 远程代码执行 (CVE-2021-42013)批量检测工具:Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点,发现 Apache HTTP Server 2.4.50 中针对…


CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via…

Remote Code Execution exploit for Apache servers. Affected versions: Apache 2.4.49, Apache 2.4.50

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

Windows Remote Desktop Services Vulnerability Allows Remote Code Execution

CVE-2024-4577 Mass Scanner & Exploit Tool

Generate SSRF payloads