

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection

REC Exploit is a Python-based security testing tool that automates detection of potential RCE conditions in web applications under authorized…

Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.

使用burp自动检测CVE-2025-55182 Next.js RCE 漏洞





Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

PoC script for CVE-2024-24919 vulnerability. It scans a list of target URLs to identify security issues by sending HTTP POST requests and analyzing…

Automatic Mass Tool for checking vulnerability in CVE-2022-4060 - WordPress Plugin : User Post Gallery <= 2.19 - Unauthenticated RCE

For detection of sitecore RCE - CVE-2021-42237

Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.

Check list of URLs against Log4j vulnerability CVE-2021-44228