
CVE-2025-55182
PoC, Hunting React2Shell about CVE-2025-55182

PoC, Hunting React2Shell about CVE-2025-55182
Python exploit for CVE-2022-28171 targeting Hikvision Hybrid SAN devices, automating blind SQL injection and command injection to achieve remote code…

There are many cheat sheets out there, but this is mine.

This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

Know a plugin has a php object exploit but need to find which lib to use?

Find out a modified Cacti public exploit!

CVE-2012-1823 exploit for https user password website.

CVE-2024-10914_Manual testing with burpsuite

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

Proof-of-concept exploit for CVE-2024-27173 targeting Toshiba e-Studio devices with remote command execution. Includes Shodan and FOFA dorks for…

There is a classic heap overflow when eval a string which large enough in Chakra! This issue can be reproduced steadly in uptodate Edge in Win10 WIP.…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects

Burp plugin able to find reflected XSS on page in real-time while browsing on site

A tool to find and exploit servers vulnerable to Shellshock

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.