
hackbox
HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Python script to test CVE-2022-44149 router vulnerability via authenticated payload delivery to the web interface, with logging for security…

Java-based tool to detect and test for CVE-2022-22965 (Spring4Shell) vulnerability in web applications, enabling security validation and exploitation…

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using…

Batch vulnerability detection tool for CVE-2022-35914. Scans multiple URLs from a target file to identify exploitable instances of this specific web…

Exploit tool for CVE-2025-64459, targeting SQL injection vulnerabilities in Django applications. Enables automated testing and exploitation of…

Proof-of-concept exploit for CVE-2023-36143 demonstrating command injection in Maxprint Maxlink 1200G v3.4.11E via the diagnostic tool web interface.

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

CVE-2025-40554 Exploitation

Detection artifact generator for SolarWinds Web Help Desk pre-auth RCE chain (CVE-2025-40552 + CVE-2025-40553). Verifies authentication bypass and…

Automated NoSQL database enumeration and web application exploitation tool.

CVE-2019-11076 - Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request

PoC for CVE-2024-25641 Authenticated RCE on Cacti v1.2.26

PoC exploit for CVE-2025-32778: command injection in Web-Check OSINT tool