
CVE-2026-58457
PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

Python script to test CVE-2022-44149 router vulnerability via authenticated payload delivery to the web interface, with logging for security…

Deserialization payload generator for a variety of .NET formatters

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

CVE-2023-38831 winrar exploit generator

An automated XSS payload generator written in python.

Log4j jndi injects the Payload generator

Exploit script targeting 5 Apache Struts RCE vulnerabilities (CVE-2013-2251, CVE-2017-5638, CVE-2017-9805, CVE-2018-11776, CVE-2019-0230) with PHP…

Post-authentication reverse shell exploit for Webmin <=1.984 leveraging CVE-2022-0824 File Manager privilege escalation. Downloads and executes a CGI…

ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)

ZIP File Raider - Burp Extension for ZIP File Payload Testing

Detection artifact generator for FortiWeb CVE-2025-25257, exploiting unauthenticated SQL injection to achieve remote code execution via hex-encoded…

Proof-of-concept exploit for CVE-2020-17530 (Apache Struts2 S2-061) with OGNL injection payload for remote code execution testing.

Single-file Python scanner for CVE-2026-48907 (Joomla JCE Editor RCE). Detects Joomla/JCE, performs intrusive math-verified payload test, supports…

Generates detection artifacts for Oracle E-Business Suite CVE-2025-61882 by serving a reverse shell payload to verify pre-auth RCE.

Web vulnerability scanner focused on automated XSS/CSP bypass payload testing and batch SQL injection detection, using SQLMap and reporting only…

Java-based exploit for Apache Batik SSRF to RCE (CVE-2022-40146) with payload generation via jar and ecmascript, enabling remote class loading…

Python-based detection artifact generator for CVE-2025-57819, exploiting FreePBX pre-auth RCE via SQL injection and auth bypass to deploy webshells…