
LANs.py
ARP spoofing and MITM tool for intercepting HTTP/FTP/IMAP/POP3/IRC traffic, injecting HTML/JS, DNS spoofing, and WiFi deauth jamming on local…

ARP spoofing and MITM tool for intercepting HTTP/FTP/IMAP/POP3/IRC traffic, injecting HTML/JS, DNS spoofing, and WiFi deauth jamming on local…

Automated penetration testing tool for discovering and retrieving log and config files via path traversal vulnerabilities, with async scanning,…

Multi-threaded batch detection and exploitation tool for Apache HTTP Server path traversal vulnerabilities CVE-2021-41773 and CVE-2021-42013,…

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

Batch vulnerability scanner and exploit tool for CVE-2022-1388 (F5 BIG-IP RCE). Performs mass detection and exploitation of unauthenticated remote…

Automated CVE-2020-5902 detection and exploitation tool for F5 BIG-IP TMUI, supporting single/batch vulnerability checks, file read/write, user…

Exploitation and detection tool for CVE-2023-22518 targeting Confluence servers, with support for multiple domains, proxy, timeout, and verbose…

City-level reconnaissance and exploitation tool for Hikvision IP cameras, DVRs, and NVRs. Uses Shodan discovery, default credential backdoor…

GUI-based tool for collecting and validating vulnerability information, with selectable exploit modules for testing specific CVEs like CVE-2020-14882…

Go-based scanner and exploit tool for CVE-2023-35078, supporting single URL and batch file input for automated vulnerability exploitation.

Batch scanner and exploit tool for CVE-2024-28255, an RCE in OpenMetadata. Supports single or multiple targets with threading, saves results to file.

Asynchronous scanner and exploit tool for CVE-2025-5777 (CitrixBleed 2) that detects memory leaks in NetScaler ADC/Gateway and extracts sensitive…

Mass scanner and exploit tool for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Features FOFA/Shodan integration,…

Proof-of-concept exploit for CVE-2017-5487 (WordPress REST API content injection) with an accompanying tool for testing and demonstration.

Python-based tool for detecting and exploiting GeoServer unauthenticated remote code execution (CVE-2024-36401). Supports single URL or list…

Automated scanner and exploit tool for CVE-2021-26855 targeting Microsoft Exchange servers, enabling remote code execution on vulnerable instances…

Multi-threaded WordPress user enumeration and login brute force tool with configurable attack aggressiveness, batch sizes, and thread count for…

Go-based PoC for Ghost CMS Content API SQL injection (CVE-2026-26980). Verifies vulnerability, extracts admin credentials and API secrets, and…