
CVE-2018-8174-exp
Python-based exploit for CVE-2018-8174 targeting Internet Explorer via crafted RTF file, enabling remote code execution with netcat reverse shell…

Python-based exploit for CVE-2018-8174 targeting Internet Explorer via crafted RTF file, enabling remote code execution with netcat reverse shell…

CVE-2022-1388, bypassing iControl REST authentication

TelerikUI Vulnerability Scanner (CVE-2019-18935)

This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)

Proof-of-concept exploit for CVE-2021-43798, a Grafana directory traversal vulnerability. Automates exploitation with a Python script to read…

Shell-based scanner for CVE-2022-1388 (F5 BIG-IP iControl REST unauthenticated RCE). Checks target IPs for the vulnerability and reports exploitable…

Exploit for CVE-2022-4539 that spoofs X-Forwarded-For headers to bypass WordPress WAF IP-based login and logging restrictions. Includes scalable…

Python exploit for CVE-2021-22986, enabling unauthenticated RCE on F5 BIG-IP and BIG-IQ via iControl REST, with command execution, batch scanning,…

Docker-based lab environment for exploiting Shellshock (CVE-2014-6271) via CGI scripts, demonstrating remote command injection through crafted HTTP…

Proof-of-concept exploit for CVE-2022-30190 (Follina). Generates malicious docx files and hosts a server to trigger remote code execution via…

CVE-2017-10271

Python-based exploit generator for CVE-2018-8174, producing malicious RTF files delivered via HTML pages with reverse shell callback capability.

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.