
CVE-2024-3400
Exploit script for CVE-2024-3400, a command injection in PAN-OS GlobalProtect, allowing unauthenticated remote code execution with root privileges.…

Exploit script for CVE-2024-3400, a command injection in PAN-OS GlobalProtect, allowing unauthenticated remote code execution with root privileges.…

CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that…

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…


Exploit script for CVE-2023-46747 (F5 BIG-IP TMUI RCE) enabling unauthenticated user creation, token retrieval, and remote command execution on…

Manual exploit script for CVE-2004-2687 (distccd RCE) that spawns a reverse shell via netcat without Metasploit, targeting remote hosts for…

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…

CVE-2025-52691 PoC: Based on watchtowr's article WT-2026-0001 about an authentication bypass exploit, this one is a functional Python attack script.

PowerShell script that audits Windows service binaries for writable permissions, identifying privilege escalation vectors by checking ACLs on…

Este script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para…

Shell script to detect CVE-2019-14287 sudo privilege escalation vulnerability. Scans systems for the flaw and reports affected configurations.

Python script to exploit a privilege escalation vulnerability in the WP REST API FNS WordPress plugin, allowing unauthenticated creation of…

Automated exploit script for CVE-2023-42793 targeting TeamCity, enabling token manipulation and admin user creation for penetration testing.

PoC for triggering buffer overflow via CVE-2020-0796

Credsleaker allows an attacker to craft a highly convincing credentials prompt using Windows Security, validate it against the DC and in turn leak it…

Arduino Rubber Ducky Framework

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)