
iodine
Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

Tunnel IPv4 data through DNS servers to bypass firewall restrictions and provide covert network access for penetration testing.

A Python script to exploit CVE-2022-36446 Software Package Updates RCE (Authenticated) on Webmin < 1.997.

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

A utility to use the usermode shellcode from the DOUBLEPULSAR payload to reflectively load an arbitrary DLL into another process, for use in testing…

CVE-2023-50254: PoC Exploit for Deepin-reader RCE that affects unpatched Deepin Linux Desktops. Deepin Linux's default document reader…

This is a script written in Python that allows the exploitation of the Metabase's software security flaw described in CVE-2023-38646.

Generates obfuscated .lnk files exploiting CVE-2026-21510 with LNK stomping, encrypted payloads, and anti-forensics for authorized penetration…

Nuclei template to detect OpenSSH servers vulnerable to CVE-2024-6387 (regreSSHion) by checking software version.

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

Proof-of-concept exploit for CVE-2024-20467, a remote denial-of-service vulnerability in Cisco IOS XE Software. Sends crafted fragmented IPv4 packets…

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

Proof-of-concept exploit for CVE-2025-22604, a remote code execution vulnerability in Cacti network monitoring software. Enables authenticated RCE…

Proof-of-concept exploit for CVE-2023-27350, a remote code execution vulnerability in PaperCut print management software, enabling unauthenticated…

According to researchers with Rapid7, over 110,000 devices appear on internet, which run stable Samba versions, while 92,500 seem to run unstable…

Pentest tool for antivirus evasion and running arbitrary payload on target Wintel host

Proof-of-concept for local privilege escalation in Avira Security via arbitrary file move, exploiting junction points to load a malicious DLL into a…

Apache CouchDB 3.2.1 - Remote Code Execution (RCE)