
Log4ShellAuditor
An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

Rocket Lms Auto Register

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.


Try to reproduce this issue with Docker

Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework

Gogs RCE via argument injection in git rebase (CWE-88) — Python PoC. CVE-2026-52806

Auto exploitation tool for CVE-2024-24401.

Mass Auto Exploit CVE-2022-4395 Unauthenticated Arbitrary File Upload


WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover