
XSS2Shell-CVE-2026-64638
Exploits CVE-2026-64638 to convert cross-site scripting into shell access on vulnerable web applications, automating payload delivery and…

Exploits CVE-2026-64638 to convert cross-site scripting into shell access on vulnerable web applications, automating payload delivery and…

Jenkins Git Client RCE CVE-2019-10392_Exp


This repo describe how to exploit unrestricted file upload vulnerability on SiteMagic CMS 4.4.2

This is Metasploit module who exploit the command injection vulnerability in control center of the agent Tesla.

Adobe Experience Manager Childlist Selector - Cross-Site Scripting

Rubbish SQLI that requires Admin

Authenticated Remote Command Execution – pfSense <= 2.1.3

Got My CVE Published CVE-2023-41575

automated SQL injection for QCubed profile.php file

Men Salon Management System Using PHP and MySQL

unauthenticated booking logic flaw in Easy!Appointments v1.5.1 causing denial of service.

Python exploit for CVE-2025-70559 targeting an upload directory bypass/remote code execution; run with LHOST and LPORT to establish a reverse shell.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities