
parameth
This tool can be used to brute discover GET and POST parameters

Go-based exploit for CVE-2021-29447 targeting WordPress 5.6.2 with PHP 8. Generates a malicious .wav payload to retrieve arbitrary files from the…

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

weaponized tool for CVE-2020-17144

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

An exploit for Four-Faith routers to get a reverse shell

Exploit for CVE-2022-46169

Small backdoor using cookie.

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

Python-based exploit for CVE-2017-8056 targeting XML-RPC denial-of-service vulnerability in web applications.

test for CVE-2018-6574: go get RCE pentesterlab

This script allows for remote code execution (RCE) on Oracle WebLogic Server

Exploit script for CVE-2025-50946

Remote shell on CVE-2009-4623

Script to automate PUT HTTP method exploitation to get shell

This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help…