
CVE-2024-22120-RCE
Time Based SQL Injection in Zabbix Server Audit Log --> RCE

Time Based SQL Injection in Zabbix Server Audit Log --> RCE

Exploit for CVE-2023-46747, a remote code execution vulnerability in F5 BIG-IP, allowing unauthorized user creation and command execution.

Proof-of-concept exploit for CVE-2022-23808, a stored XSS vulnerability in phpMyAdmin 5.1.1 setup script, with payload and reproduction steps for…

exploit for CVE-2017-1000486 vulnerability with SOCKS proxy support

CVE-2020-8636 authenticated remote code execution exploit for Opmon

A Proof of Concept (PoC) exploit for CVE-2025-70886, a persistent denial-of-service vulnerability in Halo CMS (v2.22.4 and earlier) that allows…

Modular multi-language webshell for web post-exploitation with PHP, JSP, and ASPX agents. Features defense evasion, C2 mode, and Python-based core…

✉️ HTML Smuggling generator&obfuscator for your Red Team operations

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

a unique framework for cybersecurity simulation and red teaming operations, windows auditing for newer vulnerabilities, misconfigurations and…

autonomous red teaming platform; multi-agent offensive-security meta-harness

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

A front-end JavaScript toolkit for creating DNS rebinding attacks.

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.

CVE-2024-21683 Confluence Post Auth RCE

exploit for cve-2023-47246 SysAid RCE (shell upload)

GUI Exploit Tool for CVE-2020-0688(Microsoft Exchange default MachineKeySection deserialize vulnerability)

Simulated environment for CVE-2025-20029 using Docker. Includes PoC and auto-reporting.