
CrackQL
GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Stock vulnerable wordpress RCE poc for wp2shell.

CVE-2026-45504 Microsoft Exchange File Read

Python exploit for CVE-2019-19781 targeting Citrix ADC with template injection to achieve remote code execution on vulnerable gateways.

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

CVE-2020-0688 - Exchange

PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM

Weblogic Unrestricted File Upload

Struts2 S2-045(CVE-2017-5638)Exp with GUI

cve-2024-42327 ZBX-25623

CVE-2023-7028

Python exploit for CVE-2025-64446 targeting FortiWeb WAF, enabling unauthorized user creation and privilege escalation through a crafted HTTP request.

CVE-2022-22965 poc including reverse-shell support

A PoC exploit for CVE-2019-15107 - Webmin Remote Code Execution

ScriptCase Pre-Authenticated Remote Command Execution exploitation script (CVE-2025-47227, CVE-2025-47228).

BoltWire v6.03 vulnerable to "Improper Access Control"

Apache OfBiz vulns

just record for myself