
pentest-copilot
AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…

Joomla - Component Google Map Landkarten <= 4.2.3 - SQL Injection

CMS Made Simple < 2.2.10 - SQL Injection (rewritten for python3), CVE-2019-905

Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Automates CVE-2026-42945 exploitation in NGINX containers: verifies vulnerable targets, brute-forces heap offsets, executes commands, and opens an…

Some Pentest Tools. Install and keep up to date some pentesting tools. I used this to pass my OSCP exam.

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

CVE-2019-13498

Exploiting TP-Link Archer CR-700 Router. (Responsibly Disclosed to TP-Link)

Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and…

Proof-of-concept exploit for CVE-2025-29927, a Next.js middleware authorization bypass. Includes a vulnerable target lab and Python script to verify…

Python exploit for CVE-2026-23744 in MCPJam Inspector 1.4.2, enabling remote code execution via reverse shell on target HTTP servers.

Metasploit RCE on HFS 2.3 - CVE-2014-62

Python 3 exploit for CVE-2019-9053 (SQL injection) with hash-cracking, updated from outdated Python 2 code for TryHackMe CTF use.

CVE-2023-44451, CVE-2023-52076: RCE Vulnerability affected popular Linux Distros including Mint, Kali, Parrot, Manjaro etc. EPUB File Parsing…

Exploit for CVE-2021-43857 in Gerapy v0.9.7, providing a reverse shell via authenticated project creation and command injection.

Sets up a Dockerized WebCalendar environment to demonstrate CVE-2012-1495 exploitation using Metasploit on Kali Linux.