
discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

Mass scanner for Joomla Helix3 CVE-2026-49049 that uploads PHP test payloads via com_ajax and detects executed (RCE) or raw PHP responses.

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

Page Builder CK for Joomla - Unauthenticated SSRF / Remote File Write leading to PHP execution Exploiter

Single-file Python scanner for CVE-2026-48907 in Joomla! JCE Editor, featuring multi-source fingerprinting, WAF detection, threaded bulk scanning,…

Single-file Python scanner for CVE-2026-48907 (Joomla JCE Editor RCE). Detects Joomla/JCE, performs intrusive math-verified payload test, supports…

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

GUI-based scanner and exploit tool for CVE-2026-42588 (ActiveMQ RCE). Supports VPS payload delivery and DNSLog-based vulnerability verification with…

CVE-2025-55182 Exploit Tool – Python 2.7 exploit for Next.js prototype pollution leading to RCE

Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions

Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

Multi-threaded scanner for detecting Next.js Server Action RCE vulnerabilities (CVE-2025-55182) with confidence-based scoring, WAF bypass payloads,…

Python-based RCE detection tool that sends crafted POST requests, analyzes responses for execution indicators, and supports batch scanning with…

Unauthenticated RCE exploit for CVE-2023-43208 in Mirth Connect via XML deserialization, with version detection, bulk scanning, and interactive PTY…

Automated mass exploit scanner for CVE-2025-56399 targeting Laravel File Manager RCE. Uploads and verifies PHP shells via unauthenticated file upload…