


Stock vulnerable wordpress RCE poc for wp2shell.

Using this script, you can enumerate Usernames and passwords of Nosql(mongodb) injecion vulnerable web applications.

Small Python library that makes it easy to exploit race conditions in web apps with Requests.

Blind SQL injection exploitation tool written in ruby.


Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

Simple script to automate brutforcing blind sql injection vulnerabilities

SqlMap_BurpSuite

A script for automatize boolean-based blind SQL injections (MVP).

A Burp Extender plugin, that will deserialized java objects and encode them in XML using the Xtream library.


my poc for CVE-2026-53787

Proof of concept (POC) for CVE-2026-23489 GLPI "Fields" plugin <= 1.23.2

Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research

The Clickjacking Exploit Detector uses webpage scanning techniques to identify potential vulnerabilities and provide analysis of those elements.

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.

Apache Flink Dashboard未授权访问-远程代码命令执行