
xmlrpc-bruteforcer
An XMLRPC brute forcer targeting Wordpress written in Python 3. (DISCONTINUED)

An XMLRPC brute forcer targeting Wordpress written in Python 3. (DISCONTINUED)

Exploit for CVE-2023-4427 targeting Chrome 117 V8, using many cross-origin iframes to brute-force ASLR and achieve code execution. Provides…

Python exploit for CVE-2020-9047 targeting exacqVision Web Service. Supports Windows/Linux payload delivery, remote command execution, and…

Full exploit for CVE-2019-13764 targeting V8 JavaScript engine on Linux, with root cause analysis and proof-of-concept code from Haboob Research Team.

Python exploit for CVE-2019-11043 targeting PHP-FPM buffer underflow to achieve remote code execution via null byte overwrite and FastCGI variable…

Proof-of-concept exploit for authenticated remote code execution (CVE-2021-44827) targeting TP-Link Archer C20i routers. Provides post-exploitation…

Reflected cross-site scripting (XSS) proof-of-concept exploit for CVE-2023-29808 targeting the /index.php?map=overview&findme= endpoint in cmaps…

Exploit for Fastjson RCE (CVE-2026-16723) targeting versions 1.2.68 to 1.2.83. Generates JAR and JSON payloads, hosts HTTP server, and establishes…

proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198

Python-based exploit for CVE-2025-30208 targeting Vite dev server arbitrary file read. Supports single-target detection, custom file paths, system…

Automated exploitation toolkit for CVE-2025-24813 targeting Apache Tomcat insecure session deserialization. Features multi-target scanning, gadget…

CVE-2025-55182 payload

CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool

a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.

Proof-of-concept exploit for CVE-2026-23744, targeting /api/mcp/connect to achieve remote command execution on Linux systems via reverse shell.

Cross-platform remote code execution exploit for GNU Inetutils telnet (versions 1.9.3 to 2.7), targeting CVE-2026-24061 with a simple command-line…

Shell-based exploit for CVE-2024-32002, a Git submodule RCE vulnerability, targeting Linux systems through crafted recursive clone operations.

Python-based exploit for CVE-2017-8056 targeting XML-RPC denial-of-service vulnerability in web applications.