
wp2shell
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
Exploit for CVE-2024-21754 targeting insufficient password hashing in FortiOS and FortiProxy, enabling privileged attackers to decrypt backup files…

A friend of SQLmap which will do what you always expected from SQLmap.

Blind SQL injection brute force.

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

Proof-of-concept exploit for user enumeration vulnerability in Supravizio BPM 10.1.2 via password recovery response differences, enabling brute force…

An XMLRPC brute forcer targeting Wordpress written in Python 3. (DISCONTINUED)

User Enumeration vulnerability in Kaiten (workflow management system)

Exploit for CVE-2014-4210 targeting WebLogic deserialization, with post-exploitation features including ransomware deployment, C2 integration, and…

Demonstrates a brute-force attack bypassing two-factor authentication in Nagios Fusion due to missing rate limiting and lockout, with CVE-2025-60424…

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…

wide range mass audit toolkit

Password cracking utility

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

Python utility for automating CVE-2024-4956 path traversal exploitation with mass file extraction, plus custom Hashcat module for cracking Apache…

The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

Python PoC for CVE-2023-6063, an unauthenticated time-based blind SQL injection in WP Fastest Cache <=1.2.2, extracting WordPress password hashes and…