
CVE-2022-44877
Bash script to detect and exploit CVE-2022-44877 command injection vulnerability in CentOS Web Panel, supporting single URL scanning, exploitation,…

Bash script to detect and exploit CVE-2022-44877 command injection vulnerability in CentOS Web Panel, supporting single URL scanning, exploitation,…

Python exploit for CVE-2025-4380, a Local File Inclusion vulnerability in the Ads Pro WordPress plugin. Supports single and mass target scanning with…

Go-based exploit for CVE-2024-34102, an XXE vulnerability in Adobe Commerce leading to remote code execution. Supports single and batch URL scanning…

A hands-on vulnerability assessment and exploitation of a Windows 7 VM using the EternalBlue (CVE-2017-0143) exploit. Includes scanning, exploitation…

Educational lab demonstrating Shellshock (CVE-2014-6271) exploitation using Metasploit against Metasploitable 2, including scanning, exploitation,…

Exploit scripts and nuclei templates for CVE-2024-51378 (CyberPanel vulnerability). Includes single/multi-threaded Python scanners for vulnerable…

Exploit script for CVE-2021-3773 (Port Shadow) targeting OpenVPN servers using Netfilter NAT. Performs deanonymization and man-in-the-middle attacks…

Python script to detect and exploit CVE-2021-42013 path traversal and remote code execution in Apache 2.4.50, with bulk scanning and a Docker lab for…

Static analysis tool to detect homoglyph substitution attacks in source code, scanning Python identifiers for visually similar Unicode characters to…

Python proof-of-concept for CVE-2026-5615, a stored XSS in VvvebJs, demonstrating SVG upload exploitation with multi-threaded scanning and validation.

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

Exploit tool for CVE-2026-22785, a critical code injection in orval < 7.18.0. Provides shell command execution and file scanning to demonstrate the…

Hands-on lab to exploit Apache 2.4.49 path traversal (CVE-2021-41773) using Docker, Nmap scanning, and curl to retrieve a flag.

Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

CVE-2026-53264 - Draft


Educational CVE proof-of-concept repository with setup guidance for authorized vulnerability research using virtual machines, Docker, and isolated…