
FaceBrute
Facebook brute forcer script

Facebook brute forcer script

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

Weblogic Unrestricted File Upload

PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

CVE-2019-9053 Exploit for Python 3


Remote Code Execution Vulnerability in Webmin


CVE-2004-1769 // Mass cPanel Reset password

XSS via Host Header injection and Steal Password Reset Token of another user

This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)

cve-2023-22515的python利用脚本

CVE-2025-58434 Proof of Concept