
xss2shell
Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

Simulates the Windows PE loader to identify DLL hijacking vulnerabilities, generates weaponized DLLs with shellcode payloads, and detects UAC…

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Mass scanner for Joomla Helix3 CVE-2026-49049 that uploads PHP test payloads via com_ajax and detects executed (RCE) or raw PHP responses.

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

GUI-based exploit tool for CVE-2020-5902 (F5 BIG-IP RCE) with batch target scanning, command execution, reverse shell, and file upload capabilities.

Burp Suite plugin for automated blind XSS detection with active and passive scanning, customizable OOB payloads, and configurable parameters for…

Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.

漏洞利用,Vmware vCenter 6.5-7.0 RCE(CVE-2021-21972),上传冰蝎3,getshell

Automated PHP-CGI parameter injection exploit tool targeting CVE-2024-4577 and CVE-2024-8926. Supports command execution, file upload/download, WAF…

Automated scanner and exploit for CVE-2025-34085, an unauthenticated RCE in the WordPress Simple File List plugin. Supports multi-target scanning,…

Agent dispatcher that launches security tools and sends structured results to the Faraday platform. Supports custom executors and integrates with…

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

Minimal Kali Linux Docker base image for building custom penetration testing environments. Install tools like Metasploit and sqliv2 for security…

CVE-2025-55182 RCE vulnerability in Next.js/React RSC servers (exploit and scanner)

Scanner and exploit for CVE-2024-4577 PHP CGI argument injection vulnerability. Detects susceptible PHP applications and executes arbitrary code via…

Proof-of-concept scanner for Stored Cross-Site Scripting (XSS) in WP-Statistics plugin (CVE-2025-9816). Detects and demonstrates exploitation via…