
WP-CVE-2026-87902
Read-only PHP diagnostic script that checks WordPress version, core checksums, extra PHP files, and known plugin paths for CVE-2026-87902 exposure…

Read-only PHP diagnostic script that checks WordPress version, core checksums, extra PHP files, and known plugin paths for CVE-2026-87902 exposure…

School project - Please use other repos for actual testing

Simple script to attempt a Bypass on a server possibly vulnerable to CVE-2025-29927 (Next.js Middleware)

Exploit for CVE-2026-1657, an unauthenticated image upload vulnerability via the 'ep_upload_file_media' AJAX endpoint, allowing remote file upload.

Scanner and exploit tool for CVE-2026-22730, a SQL injection in Spring AI's MariaDB vector store. Supports time-based detection, GET/POST methods,…

Authenticated SQL injection scanner for Koha Library Management System (CVE-2026-31844) using boolean-based blind technique to verify vulnerability…

Batch vulnerability scanner for CVE-2026-39363 in Vite dev server, exploiting WebSocket origin validation bypass to read arbitrary files via…

Nuclei template for detecting CVE-2026-1107 in EyouCMS, exploiting path traversal in check_userinfo to read arbitrary files and potentially achieve…

Exploit script for CVE-2026-0740 targeting Ninja Forms file upload endpoints to upload a PHP shell, scanning a list of URLs and logging successful…

WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload

Proof-of-concept for CVE-2026-12352, an authentication bypass in Digi PortServer TS that discloses device configuration including plaintext RADIUS…

Python proof-of-concept for CVE-2026-33032 that inspects nginx status and configs, then demonstrates unauthorized config write with reload to deploy…

XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation…

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Nuclei templates for drupal vulns... far from perfect

Detects CVE-2025-64446 authentication bypass in FortiWeb by exploiting a path traversal to confirm vulnerability, without administrative actions.

SSTI Exploit Detector is a tool designed to detect potential Server-Side Template Injection (SSTI) vulnerabilities in web applications.