
CVE-2026-87796
Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with…

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with…

Multi-threaded Python scanner for CVE-2026-23550, detecting unauthenticated admin takeover in WordPress Modular DS plugin with full wp-admin…

Multi-threaded scanner for CVE-2025-61882 in Oracle E-Business Suite, exploiting HTTP request smuggling to achieve unauthenticated remote code…

Proof-of-concept exploit for CVE-2026-41940, demonstrating authentication bypass in cPanel/WHM via CRLF injection and session poisoning to gain…

Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions

Exploit for CVE-2024-4040 affecting CrushFTP server in all versions before 10.7.1 and 11.1.0 on all platforms

A flexible internet crawler used for scanning technologies, instances and vulnerabilities worldwide across the internet.

xpath is a fast, multi-technique XPath injection scanner written in Nim. It focuses on practical detection, response comparison, visible extraction,…

WordPress HTMega Unauthenticated PII Disclosure Exploit (CVE-2026-4106)

php-cli vulnerability scanner

Proof-of-concept exploit for CVE-2021-41730, demonstrating remote command execution in TENDA AC15/AC6 routers via unvalidated formSetIptv()…

CVE-2024-4956 : Nexus Repository Manager 3 poc exploit

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

BIG-IP F5 Remote Code Execution

CVE-2026-0740

Docker-based multi-stage attack emulation lab demonstrating CVE-2017-5638 and CVE-2021-41773 exploitation, lateral movement, and Suricata IDS…

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

This is a POC for testing your projects that are vulnerable to CVE-2025-55182 with a terminal and ability to scan a list