
Terrminus-CVE-2026-2406
AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive…

AsyncIO Scanner & Exploitation Framework for CVE-2026-24061 (Telnet NEW_ENVIRON Auth Bypass). Features high-concurrency discovery, passive…

Proof-of-concept exploit for CVE-2026-25939, an unauthenticated authorization bypass in FUXA SCADA software allowing arbitrary scheduler manipulation…


ICS-Park Smart Park Management System v2.0

PoC Modbus TCP exploit demonstrating spoofed writes to read-only coils in simulated PLCs, highlighting SCADA/ICS access control flaws.

This repository contains a few vulnerabilities that were found and reported during vulnerability assessments.

PoC C&C for the Industroyer malware

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

ISAF aims to be a framework that provides the necessary tools for the correct security audit of industrial (OT) environments.

OpenPLC 3 WebServer Authenticated Remote Code Execution.

OpenPLC 3 WebServer Authenticated Remote Code Execution.

CVE-2018-7843

Proof of Concept (PoC) for CVE: 2017-16744 and 2017-16748

Exploit for Authenticated Remote Code Execution on OpenPLC v3 Webserver

Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports…

DoS exploit for CVE-2015-5374 targeting Siemens SIPROTEC 4 and Compact EN100 Ethernet modules via a crafted UDP packet to port 50000, with an…

Simple script to exploit open redirection vulnerability in Rockwell ControlLogix 1756-ENBT/A

PoC exploit for CVE-2025-69985: authentication bypass leading to RCE in FUXA SCADA ≤1.2.8. Includes a modular Python exploit with interactive shell,…