
CVE-2023-38035-MobileIron-RCE
Script to exploit CVE-2023-38035

Script to exploit CVE-2023-38035

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

Shattered is a tool and POC for the new CrushedFTP vulns, CVE Exploit Script: CVE-2025-2825 vs CVE-2025-31161

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Directory traversal in Gitea and Forgejo's repository‑template processing allows remote authenticated attackers to process arbitrary files on the…

Research into CVE-2022-41853: Using static functions to obtian RCE via Java Deserialization & Remote Codebase Attack

Demonstrates a PHP object injection attack targeting CVE-2023-41892, including exploitation techniques and mitigation strategies for securing PHP…

Proof-of-concept exploit for CVE-2025-12137 demonstrating local file disclosure via a WordPress plugin's REST API importer endpoint. Includes…

Multi-threaded Python PoC scanner for CVE-2023-49103 that checks large URL lists for exposed phpinfo() output with .htaccess bypass via /.css path…

This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id:…

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Proof-of-concept demonstrating a Node.js permission model bypass (CVE-2026-21636) that allows network access via undici/fetch to local services,…

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

Proof-of-concept exploit for CVE-2023-41993, a WebKit JIT type confusion in Safari. Provides addrof/fakeobj primitives via heap manipulation and…

Automatic SQL injection and database takeover tool