
CVE-2026-19478-PoC
Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…


fsociety Hacking Tools Pack – A Penetration Testing Framework

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021

CVE-2025-30208-EXP

A FreeSWITCH specific scanning and exploitation toolkit for CVE-2021-37624 and CVE-2021-41157.

CVE-2025-26202

CVE-2021-42560: Unsafe XML Parsing in MITRE Caldera

Automated NoSQL database enumeration and web application exploitation tool.

Inject code and spy on wifi users

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

Efficient and advanced man in the middle framework

:new: The Multi-Tool Web Vulnerability Scanner.

Notes about attacking Jenkins servers

weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-20…

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

The Offensive Manual Web Application Penetration Testing Framework.