
CVE-2024-23897
PoC and scanner for CVE-2024-23897 targeting Jenkins <= 2.441 & LTS 2.426.2. Supports single targets, CIDR ranges, file reading, and CLI command…

PoC and scanner for CVE-2024-23897 targeting Jenkins <= 2.441 & LTS 2.426.2. Supports single targets, CIDR ranges, file reading, and CLI command…

Exploit tool for CVE-2025-55182 and CVE-2025-66478 in React Server Components and Next.js, featuring RCE gadgets, file read/write, OOB callbacks, and…

Python-based exploit for CVE-2022-1388, an F5 BIG-IP iControl REST authentication bypass leading to remote code execution. Supports single URL,…

Offensive security tool for printer pentesting

A vulnerability scanner that detects CVE-2021-21980 vulnerabilities.

CVE-2026-48611- authentication bypass in phpBB

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

Update WINRE.WIM file to fix CVE-2022-41099

Quick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

CVE-2025-56399 – Remote Code Execution in laravel-file-manager v3.3.1. Exploits misconfigured config in Laravel File Manager to upload and verify a…

YARA-based file scanner that monitors directories, detects malware in document archives, and outputs CSV results for SIEM integration.

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

Detects and exploits Apache CVE-2021-42013 for remote code execution and local file disclosure via Nmap, Python, and Ruby scripts.

Multi-language exploit and detection scripts for CVE-2021-41773, enabling remote code execution and local file disclosure on vulnerable Apache…

Automated mass exploiter for CVE-2026-0740, an unauthenticated arbitrary file upload in Ninja Forms File Uploads plugin, enabling remote code…