
afrog
A Security Tool for Bug Bounty, Pentest and Red Teaming.

A Security Tool for Bug Bounty, Pentest and Red Teaming.

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.

Next.js-Exploit-Tool 图形化综合利用工具,基于 Go 开发,一款针对 CVE-2025-55182 的独立安全评估工具。

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)

Python script to detect FortiOS authentication bypass (CVE-2024-55591) by probing WebSocket connections to the management interface, identifying…

A go-exploit to scan for Juniper firewalls vulnerable to CVE-2023-36845

Hadoop Yan ResourceManager unauthorized RCE

Exploits GitLab authenticated RCE vulnerability known as CVE-2022-2884.

Nuclei templates and exploit resources for CRLF based desync attacks

Python exploit tool for CVE-2022-29464, enabling unrestricted file upload and remote code execution on vulnerable WSO2 products via directory…

Python-based detection artifact generator for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520,…

Detection artifact generator for FortiSIEM CVE-2025-25256 unauthenticated remote command execution vulnerability. Sends crafted packets to verify…

Go-based scanner and exploit tool for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports batch scanning, token leakage, and…

Python script to detect CVE-2024-23113, a format string vulnerability in FortiGate FGFM service on TCP/541, using SSL connection and crafted payload…

A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core

Exploitation tool for CVE-2023-22527 targeting Confluence servers, enabling remote code execution with support for multiple targets, concurrency, and…