
Project-CVE-2026-45833
Exploit tool for CVE-2026-45833 in ChromaDB, enabling malicious model generation, reconnaissance, and data exfiltration from target collections via…

Exploit tool for CVE-2026-45833 in ChromaDB, enabling malicious model generation, reconnaissance, and data exfiltration from target collections via…

Exploit tool for CVE-2017-7921 in Hikvision cameras, supporting vulnerability detection, credential extraction, and snapshot retrieval via…

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

Python PoC for CVE-2026-21010 that replays captured SIP digest Authorization headers to bypass nonce uniqueness/expiration and make unauthorized VoIP…

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…

Automated exploit tool for CVE-2021-42237 targeting SiteCore XP. Reads target URLs from a file and leverages DNSLog for out-of-band detection.

Opensvp is a security tool implementing "attacks" to be able to test the resistance of firewall to protocol level attack.

Remote Code Execution Exploit in the RPC Library

Detection artifact generator for Ivanti EPMM pre-auth RCE chain (CVE-2025-4427 + CVE-2025-4428). Executes commands to verify vulnerability status…

Tool for testing mitigations and exposure to Rapid Reset DDoS (CVE-2023-44487)

Script of Network Security Project - Attack on CVE-2021-22555

Python-based exploit tool for detecting and exploiting CVE-2018-15708 vulnerability in web applications, enabling security assessment and penetration…

Batch vulnerability detection tool for CVE-2022-35914. Scans multiple URLs from a target file to identify exploitable instances of this specific web…

Dominate the domain. Relay to royalty.

Proof-of-concept exploit for CVE-2025-14847, a MongoDB bleed vulnerability. Enables verification of vulnerable instances and understanding of attack…