
CVE-2025-23048-POC
Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…


Generic Scanner for Apache log4j RCE CVE-2021-44228

Proof-of-Concept (PoC) for CVE-2025-34028, a Remote Code Execution vulnerability in Commvault Command Center. This Python script scans single or…

A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets,…

Log4Shell (CVE-2021-44228) docker lab

A cheatsheet for exploiting server-side SVG processors.

Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.

Exploit for CVE-2024-3273, supports single and multiple hosts

Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.

CVE-2025-53690 POC

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this…

Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.

XSS exploit for CVE-2025-8550 in atjiu pybbs ≤6.0.0