
BobTheSmuggler
"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

Python-based exploit tool for CVE-2025-25257 in FortiWeb. Automates SQL injection detection, webshell upload, and remote command execution on…

CVE-2024-4577 Mass Scanner & Exploit Tool

This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests.…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

An exploitation tool for the Next.js vulnerability CVE-2025-55182 that allows remote command execution through a poisoning prototype in React Server…

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

Proof-of-concept exploit for CVE-2024-55591, enabling unauthenticated WebSocket CLI access to FortiOS devices, with interactive shell and admin…

SharePoint WebPart Injection Exploit Tool

CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify…

## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands…

CVE-2025-6934 Exploit Tool Unauthenticated Administrator Account Creation in WordPress Plugin Opal Estate Pro

This is a script written in Python that allows the exploitation of the Metabase's software security flaw described in CVE-2023-38646.

Docker-based lab to validate CVE-2021-44228 (Log4Shell) in Java apps, test mitigations, and simulate RCE via LDAP and HTTP payloads.

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test