
strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

Automatic SSTI detection tool with interactive interface

Automated Αll-in-One OS command injection exploitation tool.

Python-based exploit for CVE-2017-8056 targeting XML-RPC denial-of-service vulnerability in web applications.

A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance.

CLI tool to detect HTTP Request Smuggling vulnerabilities using time-delay analysis with built-in CL.TE and TE.CL payloads for automated security…

Fuel CMS 1.4.1 - Remote Code Execution

Automatic SQL injection and database takeover tool

XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC

Python exploit for CVE-2021-22941 targeting Citrix ShareFile RCE with shell and ping options for remote command execution and network probing.

Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Ivanti EPMM Pre-Auth RCE Chain