
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Exploit CVE-2025-14847 (MongoBleed) to disclose sensitive heap memory from MongoDB servers. Python-based scanner with detailed vulnerability reports…

🔍 Scan for MongoDB vulnerabilities with MongoBleed, a high-performance tool for detecting CVE-2025-14847 across large networks quickly and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Advanced MSSQL penetration testing tool for lateral movement, command execution, NTLM relay, and brute-force attacks via linked servers and multiple…

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Authenticated remote code execution exploit for Windows Admin Center via WinREST/PowerShell invokeCommand; takes credentials and runs arbitrary…

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

Python RCE exploit for Redis CVE-2026-25243, leveraging a RESTORE double-free and heap exploitation chain to achieve arbitrary read/write and execute…

Exploit PoC for authenticated remote code execution in Gogs through symlink-based arbitrary file write in the PutContents API, enabling SSH command…

RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0, 8.8.1

Proof-of-concept exploit for WordPress REST API time-based blind SQL injection (CVE-2026-63030, CVE-2026-60137) with full chain escalation to remote…

Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Unauthenticated remote code execution exploit for WordPress core (CVE-2026-63030 + CVE-2026-60137). Chains REST API batch route confusion with SQL…

Proof-of-concept exploit for CVE-2026-63030 (WordPress pre-auth RCE) with SQL injection detection, credential extraction, and webshell deployment.…