
social-engineer-toolkit
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Proof-of-concept exploit for OS command injection (CVE-2023-33381) in MitraStar GPT-2741GNAC routers. Demonstrates bypass of restricted shell via…

Image Payload Creating/Injecting tools

A cheatsheet for exploiting server-side SVG processors.

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

PoC for CVE-2025-22131

PoC of CVE-2024-33883, RCE vulnerability of ejs.

This project includes a python script which generates malicious commands leveraging CVE-2022-42889 vulnerability

CVE-2017-7269 to webshell or shellcode loader

Exploit PoC and root-cause analysis for a critical unauthenticated PHP object injection in WordPress Database for Contact Form 7, leading to RCE via…

CVE-2022-37201 POC

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

Explorations of CVE-2024-49368 + Exploit Development

Simple shell script for the exploit

PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original…

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

Step-by-step tutorial demonstrating how to set up a vulnerable Apache 2.4.49 environment and exploit CVE-2021-41773 path traversal using Kali Linux…