
cve-2026-41042
Exploits unauthenticated RCE in Apache Gravitino < 1.2.1 via H2 JDBC INIT; hosts SQL/Java payloads, executes commands, and exfiltrates output over…

Exploits unauthenticated RCE in Apache Gravitino < 1.2.1 via H2 JDBC INIT; hosts SQL/Java payloads, executes commands, and exfiltrates output over…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

A cheatsheet for exploiting server-side SVG processors.

Exploit for Fastjson RCE (CVE-2026-16723) targeting versions 1.2.68 to 1.2.83. Generates JAR and JSON payloads, hosts HTTP server, and establishes…

There are many cheat sheets out there, but this is mine.

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Automated man-in-the-middle attack tool.

Test and Exploit Scripts for CVE 2022-1388 (F5 Big-IP)

VMware vCenter CVE-2021-21972 Tools


Generic Scanner for Apache log4j RCE CVE-2021-44228


CVE-2025-53690 POC

Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.


The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

Barcha is your Swiss‑Army knife for SQL Injection reconnaissance 🔍. Written in Go, it automates: Shodan enumeration of SSL hosts 🕵️♂️ Liveness &…

Proof-of-Concept (PoC) for CVE-2025-34028, a Remote Code Execution vulnerability in Commvault Command Center. This Python script scans single or…