
EXPLOIT-CVE-2026-9198
Proof-of-concept exploit for CVE-2026-9198, an unauthenticated RCE in IBM Langflow OSS, chaining auto_login and validate/code endpoints. Includes a…

Proof-of-concept exploit for CVE-2026-9198, an unauthenticated RCE in IBM Langflow OSS, chaining auto_login and validate/code endpoints. Includes a…

Proof-of-concept exploit for unauthenticated remote code execution in MaxSite CMS <= 109.1 via MarkItUp editor AJAX endpoints, with detection and…

Python proof-of-concept for authenticated command injection in Hikvision wireless APs, enabling remote code execution testing with customizable…

Exploitation toolkit for RichFaces

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Proof-of-concept exploit for CVE-2026-33017 demonstrating unauthenticated remote code execution in Langflow via malicious CustomComponent injection…

Python-based detection artifact generator for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520,…

CVE-2026-56164 EOP Exploit

Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE…

Bash-based proof-of-concept exploit for CVE-2025-9074 enabling Docker container escape by mounting host Windows C: drive via vulnerable API endpoints.

Python exploit script for CVE-2020-14882 targeting Oracle WebLogic Server. Executes remote commands via crafted HTTP requests to unauthenticated…

Mass exploitation script for CVE-2021-24499, an unauthenticated arbitrary file upload vulnerability in the Workreap WordPress theme, enabling remote…

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

a lightweight JavaScript snippet showcasing how unauthorized password changes can be triggered on vulnerable Fortinet FortiSwitch GUI endpoints.

Proof-of-concept exploit for CVE-2025-55182: unauthenticated RCE in React Server Components via unsafe deserialization, enabling arbitrary command…

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

Extensible host triage tool for red teams, dynamically loading OpSec-aware checks to gather user, domain, privilege, and credential information from…