
MFASweep
A tool for checking if MFA is enabled on multiple Microsoft Services

A tool for checking if MFA is enabled on multiple Microsoft Services

Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.

POC for VMWARE CVE-2022-22954

A framework for BREACH and other compression-based crypto attacks

UPnP Pentest Toolkit for Windows

Proof-of-concept for CVE-2021-21972, a remote code execution vulnerability in vCenter Server 6.5-7.0. Verifies vulnerable paths without exploitation.

PoC exploit and NSE scanner for CVE-2021-21985, a vCenter Server RCE vulnerability in the vSAN Health Check plugin, with manual exploitation steps…

Proof-of-concept exploit for CVE-2022-22963 (Spring Cloud Function SpEL RCE). Scans URLs, executes commands, and identifies vulnerable targets.

Proof-of-concept exploit code for CVE-2016-5696

Proof-of-concept exploit for CVE-2023-36845 enabling unauthenticated remote code execution on Juniper SRX firewalls and EX switches via PHP…

Proof-of-concept exploit for CVE-2025-5419, demonstrating a critical vulnerability with a JavaScript-based implementation for security testing and…

PoC for CVE-2022-1388_F5_BIG-IP

CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)

Python exploit script for CVE-2021-26855 (Microsoft Exchange Server SSRF) with integrated ZoomEye dork for mass scanning and detection of vulnerable…

Python-based exploit and detection script for CVE-2021-21972 (VMware vCenter unauthorized RCE), using Zoomeye dork for host discovery and pocsuite3…

Proof-of-Concept for Authorization Bypass in Next.js Middleware

Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)

CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain…