
scanner-exploit-joomla-CVE-2015-8562
Automated scanner and exploit tool targeting Joomla CMS CVE-2015-8562 for remote code execution, designed for penetration testing and vulnerability…

Automated scanner and exploit tool targeting Joomla CMS CVE-2015-8562 for remote code execution, designed for penetration testing and vulnerability…

Exploit tool for CVE-2021-22205, targeting a remote code execution vulnerability in GitLab. Enables automated exploitation and security assessment.

Automated exploitation tool for CVE-2021-3019 that reads target IPs from a text file and executes the exploit against HTTP endpoints.

Exploit tool for CVE-2021-44228 (Log4Shell) targeting vulnerable Log4j instances for remote code execution and security testing.

A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs…

An XSS exploitation command-line interface and payload generator.

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

CVE-2024-24919 exploit

CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)

Passive recon & attack surface mapper — zero requests sent

MailMasta wordpress plugin Local File Inclusion vulnerability (CVE-2016-10956)

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

Go-based PoC for Ghost CMS Content API SQL injection (CVE-2026-26980). Verifies vulnerability, extracts admin credentials and API secrets, and…

Python PoC for CVE-2026-93399, an unauthenticated IDOR in Bookly <= 28.2 that leaks order tokens, exposes appointments, and rolls back bookings.

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…