
quiver
Quiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.

Quiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.

Extracts hardware random keys from NEC Aterm router firmware images and QR codes to generate valid passwords for gaining shell access.

Simple shell script for the exploit

Shell script for automated enumeration of Linux systems to identify privilege escalation vectors and configuration weaknesses.

Exploit for Marimo pre-auth RCE via terminal WebSocket, providing command execution, interactive PTY shell, and reverse shell capabilities for…

Proof-of-concept exploit for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Includes a scanner for vulnerable hosts and a…

Weaponized web shell

Shell script collection for SMB protocol auditing, vulnerability detection (EternalBlue, SMBGhost), null session enumeration, credential brute-force,…

Shell script that tests for CVE-2024-24919 by sending curl requests to specified IPs/domains, intended for educational vulnerability assessment.

A command shell wrapper using only WMI for Microsoft Windows

Python-based scanner for GitLab CVE-2021-22205 remote code execution, with Shodan integration for target discovery and reverse shell delivery.

Shell script to scan domains for CVE-2024-4577 PHP remote code execution vulnerability via crafted POST requests, exporting vulnerable targets for…

Have you ever faced with the lack of possibility of using NMap? For instance if you have reverse shell as an unprivileged user and there are no…

Python exploit for CVE-2026-42945 (NGINX Rift) with reverse shell capability and Shodan-based target discovery for penetration testing.

Single-file HTML cheat sheet for red teamers and pentesters with auto-injecting attacker/target variables, OS-aware reverse shell generator, and…

An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized…

Modular penetration testing framework with a Metasploit-like interactive shell, pre-built CVE exploit modules, and cloud/network reconnaissance…

Shell script to check Ivanti EPMM (MobileIron Core) instances for CVE-2023-35078 remote unauthenticated API access vulnerability, with Shodan dorks…