
CVE-2026-58457
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

Payload Generator

Python script to test CVE-2022-44149 router vulnerability via authenticated payload delivery to the web interface, with logging for security…

CVE-2023-38831 winrar exploit generator

Deserialization payload generator for a variety of .NET formatters

Exploit script targeting 5 Apache Struts RCE vulnerabilities (CVE-2013-2251, CVE-2017-5638, CVE-2017-9805, CVE-2018-11776, CVE-2019-0230) with PHP…

Post-authentication reverse shell exploit for Webmin <=1.984 leveraging CVE-2022-0824 File Manager privilege escalation. Downloads and executes a CGI…

ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)

Proof-of-concept exploit for CVE-2020-17530 (Apache Struts2 S2-061) with OGNL injection payload for remote code execution testing.

Generates detection artifacts for Oracle E-Business Suite CVE-2025-61882 by serving a reverse shell payload to verify pre-auth RCE.

Java-based exploit for Apache Batik SSRF to RCE (CVE-2022-40146) with payload generation via jar and ecmascript, enabling remote class loading…

Payload generator for Java Binary Deserialization attack with Commons FileUpload (CVE-2013-2186)

Python exploit script for CVE-2015-6967, enabling authenticated arbitrary file upload in Nibbleblog 4.0.3 with custom payload support.

PowerShell proof-of-concept exploit for CVE-2025-59287 targeting WSUS servers. Automates payload generation with ysoserial.net and triggers a reverse…

Python exploit script for CVE-2019-16113, an authenticated remote code execution vulnerability in Bludit CMS 3.9.2+, with reverse shell payload…

Exploit generator for CVE-2018-15982 (Adobe Flash Player) that produces SWF and HTML files for remote code execution via crafted Flash objects.

Python script exploiting JBoss Java deserialization RCE (CVE-2017-12149) using ysoserial for dynamic payload generation. Requires Java runtime.

Java-based exploit for CVE-2024-21006, delivering a payload via LDAP to a target IP and port. Includes compiled JAR and source for customization.