
harpyTools
Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Automated Active Directory post-exploitation toolkit for Kerberos ticket extraction, NTLM relay attacks, and lateral movement via NetExec, Impacket,…

Python implementation of Minsky's Universal Turing Machine with a built-in exploit demonstrating arbitrary code execution (CVE-2021-32471) for…

Proof of concept python script for regreSSHion exploit.

A python implementation of CVE-2004-2271 targeting MiniShare 1.4.1.

Python exploit for CVE-2022-22963 (Spring4Shell) targeting Spring Cloud Function RCE. Automates reverse shell delivery via wget and bash one-liner…

spring4shell | CVE-2022-22965

CVE-2023-46604-RCE exploit with Linux reverse shell payload

# CVE-2025-0282: Remote Code Execution Vulnerability in [StorkS]

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

Automatic script written in python for CVE-2009-3999

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Implementation of CVE-2022-0847 as a shellcode

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

Structured lab for controlled exploitation of CVE-2025-5548 (FreeFloat FTP Server). Includes environment setup, fuzzing, EIP control, badchars…

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

DropEngine provides a malleable framework for creating shellcode runners, allowing operators to choose from a selection of components and combine…

Step-by-step guide to exploit a buffer overflow in FreeFloat FTP Server using Python fuzzing, Immunity Debugger with mona.py, and IDA Free for binary…

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.