
RCE-CVE-2026-10520-CVE-2026-10523
Detection artifact generator for Ivanti Sentry authentication bypass and RCE vulnerabilities (CVE-2026-10520, CVE-2026-10523). Scans single or…

Detection artifact generator for Ivanti Sentry authentication bypass and RCE vulnerabilities (CVE-2026-10520, CVE-2026-10523). Scans single or…

Native Linux SQL injection scanner with classic Havij UI, supporting error-based, union-based, boolean blind, and time-based detection,…

Authorized SQL injection exploitation framework for CVE-2020-5504 in phpMyAdmin, featuring automated database enumeration, blind injection, proxy…

Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.

Modular web application security scanner with fingerprinting (server, CMS, WAF, CDN) and attack modules (SQLi, XSS, RFI, brute-force) for automated…

Unauthenticated privilege-escalation PoC for WordPress Events Manager < 7.4.1; discovers colliding post/user IDs and escalates targets to…

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

Burp Suite extension that discovers hidden, unlinked parameters using advanced diffing and binary search, enabling detection of web cache poisoning…

Python PoC exploiting time-based blind SQLi in Nagios XI to extract database contents, with multithreaded binary-search extraction and CLI…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Authenticated proof-of-concept scanner for the Joomla JCE rename vulnerability; fingerprints vulnerable versions, uploads hidden markers, verifies…

WordPress security scanner that fingerprints versions, detects reflected XSS across multiple targets concurrently, and supports an authenticated…

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

Multi-threaded exploit for CVE-2026-11961 in WordPress User Registration; detects vulnerable versions and creates admin accounts, with batch…

Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`),…