
neko
A self hosted virtual browser that runs in docker and uses WebRTC.

A self hosted virtual browser that runs in docker and uses WebRTC.

Bash-based PoC exploit for CVE-2025-9074 targeting unauthenticated Docker Engine API to achieve container escape and remote code execution via…

PHP poc, exploit for CVE-2025-9074

Step-by-step walkthrough of CVE-2017-18349 Fastjson deserialization RCE exploitation, covering attack surface identification, fingerprinting, JNDI…

Step-by-step exploit writeup for CVE-2017-11610 (Supervisord XML-RPC RCE) with attack surface analysis, namespace traversal discovery, and…

Proof-of-concept exploit for CVE-2025-32433, enabling unauthenticated remote code execution in Erlang/OTP SSH. Includes Docker setup and reverse…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Proof-of-concept exploit for CVE-2024-25082, demonstrating remote code execution in FontForge via crafted ZIP archives. Includes payload generator,…

Automated Mass Exploiter

CVE-2026-20253 - Splunk Enterprise

Proof-of-concept exploit for CVE-2026-54806: unauthenticated PHP object injection in WP Activity Log plugin enabling blind RCE via User-Agent header.…

Exploit for CVE-2024-23897 in Jenkins, enabling file read and remote code execution via crafted requests. Includes Docker setup and Groovy scripts…

Scanner and interactive exploit for CVE-2026-24061 in inetutils-telnetd, enabling pre-auth root access via crafted NEW-ENVIRON negotiation. Includes…

Python exploit scanner for Apache 2.4.50 (CVE-2021-42013) detecting path traversal and remote code execution with bulk scanning and Docker lab…

Exploit for CVE-2023-46604 in Apache ActiveMQ, enabling remote code execution via crafted XML payloads and reverse shell establishment.

Exploit and scanner for CVE-2026-24061, a telnetd authentication bypass that grants root shell via crafted USER environment variable. Includes Docker…

Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…