
CVE-2025-58434-AND-59528-POC
Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

Forti CVE-2022-40684 enumeration script built in Rust

Proof-of-concept exploit for Metabase pre-auth RCE (CVE-2023-38646) that retrieves setup token and executes arbitrary commands via base64-encoded…

Exploit script for CVE-2023-46747 (F5 BIG-IP TMUI RCE) enabling unauthenticated user creation, token retrieval, and remote command execution on…

Proof-of-concept exploit for CVE-2026-25253 in OpenClaw: a crafted gatewayUrl exfiltrates the Control UI gateway token, enabling unauthorized gateway…

Automated Python exploit for CVE-2025-69516, an SSTI vulnerability in Tactical RMM, enabling remote code execution with a session token.

Python exploit for CVE-2023-42793 that achieves remote code execution on TeamCity Linux servers by encoding a payload in a URL and sending it to the…

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Exploits for CVE-2020-9376 and CVE-2020-9377

Exploit for CVE-2026-15013: unauthenticated SAML auth bypass via algorithm confusion. Forges SAML responses to gain admin access and deploy…

CVE-2025-58434 Flowise <= 3.0.5 and earlier allows account takeover via unauthenticated forgot-password token. CVE-2025-59528 lowiseAI Custom MCP…

PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain,…

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)

Grant remote access to user account without sharing credentials