
CVE-2023-20198
Check a target IP for CVE-2023-20198 vulnerability in Cisco IOS XE web UI. Simple Python script for rapid exploitation verification.

Check a target IP for CVE-2023-20198 vulnerability in Cisco IOS XE web UI. Simple Python script for rapid exploitation verification.

BIGIP CVE-2020-5902 Exploit POC and automation scanning vulnerability

Simple Python exploit script for Apache HTTPd 2.4.49 path traversal vulnerability (CVE-2021-41773). Supports single IP and file-based scanning.

Bash script to check and exploit CVE-2022-1388 RCE in F5 BIG-IP, with a curl-based POC for command execution.

This is my exploit for CVE-2024-22120, which involves an SSRF vulnerability inside an XXE with a Gopher payload.

A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs…

Vulnerability research write-up on CVE-2017-7921 — a critical unauthenticated auth bypass in Hikvision IP cameras/DVRs/NVRs, covering root cause,…

Proof of concept for CVE-2020-5902

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface…

Proof-of-concept exploit for CVE-2020-5902, a remote code execution vulnerability in F5 BIG-IP TMUI, with file read and command execution payloads…

Multi-threaded exploit script for CVE-2024-24919 that scans a list of IP addresses and outputs results, intended for educational use.

[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)

CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys

php-cgi-cve-2024-4577

Proof-of-concept for OS command injection in Curo UC300 IP phone admin panel, demonstrating arbitrary command execution via the IP Addr parameter.

Proof-of-concept code (Bash and Python) for CVE-2025-65856 where ONVIF implementation in in Xiongmai XM530 IP cameras allows for unauthenticated …

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.