
cve-2024-24919
Shell script that tests for CVE-2024-24919 by sending curl requests to specified IPs/domains, intended for educational vulnerability assessment.

Shell script that tests for CVE-2024-24919 by sending curl requests to specified IPs/domains, intended for educational vulnerability assessment.

Shell script to scan domains for CVE-2024-4577 PHP remote code execution vulnerability via crafted POST requests, exporting vulnerable targets for…

Shell script to detect if the ssh binary is likely vulnerable to CVE-2024-3094, without requiring hexdump.

Shell script to exploit CVE-2020-13942 on web targets, with pre-scanning via httpx or httprob and batch processing from a target list.

Weaponized web shell

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

CHOMTE.SH is a powerful shell script designed to automate reconnaissance tasks during penetration testing. It utilizes various Go-based tools to…

Shell script to check Ivanti EPMM (MobileIron Core) instances for CVE-2023-35078 remote unauthenticated API access vulnerability, with Shodan dorks…

Proof-of-concept exploit for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Includes a scanner for vulnerable hosts and a…

Simple shell script for the exploit

Shell script to exploit CVE-2024-24919, enabling path traversal file retrieval from Check Point Security Gateways. Supports single IP and batch…

Shell script to exploit CVE-2020-13942, a remote code execution vulnerability in Apache Unomi, with pre-scanning via httpx or httprob.

Shell script to identify and exploit CVE-2023-43208, an unauthenticated remote code execution vulnerability in NextGen Mirth Connect before version…

Proof-of-concept exploit for PHP CGI argument injection (CVE-2024-4577) enabling remote code execution on vulnerable Windows servers with scanning…

Quiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.

Specify targets and run sets of tools against them

Have you ever faced with the lack of possibility of using NMap? For instance if you have reverse shell as an unprivileged user and there are no…

Multi-threaded time-based blind SQL injection exploit for CVE-2026-14762 targeting Hotel & Tourism Reservation 1.0. Enumerates databases, tables,…