
masta-cve-2026-48907
Single-file Python scanner for CVE-2026-48907 (Joomla JCE Editor RCE). Detects Joomla/JCE, performs intrusive math-verified payload test, supports…

Single-file Python scanner for CVE-2026-48907 (Joomla JCE Editor RCE). Detects Joomla/JCE, performs intrusive math-verified payload test, supports…

nginx CVE scanner + RCE exploit framework (CVE-2026-42945 + 16 others)

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.

Automated exploit and mass scanner for CVE-2026-5118, an unauthenticated privilege escalation in WordPress Divi Form Builder <=5.1.2, enabling admin…

A evolved version of assetnote CVE-2025-55182 scanner

cve-2026-48907 scanner

Automated scanner and exploit for CVE-2026-27384, an unauthenticated RCE in W3 Total Cache via mfunc/eval() injection. Features auto-detection, 48…

Exploit scripts and scanner for CVE-2024-27956, a WordPress plugin vulnerability, including a modified exploit with SSL verification bypass.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

CVE-2026-33017 - Langflow < 1.9.0 Unauthenticated RCE PoC

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Tools and Techniques for Red Team / Penetration Testing

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

Infection Monkey - An open-source adversary emulation platform

Automated Mass Exploiter

Trying to tame the three-headed dog.