


Public exploit for a Linux kernel zero-day (CVE-2026-31431) enabling local privilege escalation to root on distributions since 2017. Includes a…

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

pure-python implementation of MemoryModule technique to load dll and unmanaged exe entirely from memory

Python RCE exploit for Apache Spark rewritten from Metasploit module


Proof-of-concept exploit for CVE-2026-26114, a remote code execution vulnerability in Microsoft SharePoint, with a Python PoC and Metasploit module…

A fast SSH mass-scanner, login cracker, banner grabber and password auth checker tool using the python-masscan and shodan module.

Remote privilege escalation exploit for CVE-2018-1049 targeting VyOS via SSH-based command injection in a sudo-permitted Perl script, granting root…

Stealthier variation of Module Stomping and Module Overloading injection techniques that reduces memory IoCs. Implemented in Python ctypes

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

Python exploit for Drupal 8 core RESTful API RCE (CVE-2019-6340) that sends crafted requests to execute arbitrary commands on vulnerable sites.

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection…

CVE-2024-49112 LDAP RCE PoC and Metasploit Module

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

CVE-2025-4517 (CVSS 9.4 – Critical) A vulnerability in Python's `tarfile`