
CVE-2026-82222
Exploit framework for CVE-2026-82222, an unauthenticated RCE in GiveWP WordPress plugin. Supports mass scanning, auto-detection, multi-threading,…

Exploit framework for CVE-2026-82222, an unauthenticated RCE in GiveWP WordPress plugin. Supports mass scanning, auto-detection, multi-threading,…

Exploit for CVE-2016-9177 targeting Spark Java web framework, demonstrating directory traversal vulnerability in version 2.5.1 for security testing…

Exploit for CVE-2018-12542 in Vert.x-Web, a Java web framework. Demonstrates a path traversal vulnerability allowing unauthorized access to static…

Proof-of-concept exploit and testing scripts for Spring4Shell (CVE-2022-22965), a Spring Framework remote code execution vulnerability, with bash and…

Exploit toolkit targeting CVE-2019-15477 in the Jooby micro web framework, enabling vulnerability analysis and exploitation of Java/Kotlin web…

Proof-of-concept exploit for CVE-2025-43865 demonstrating pre-render data spoofing in React Router framework mode, enabling data injection during…

Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass

Exploit for CVE-2011-4367 targeting Apache MyFaces JSF implementation, demonstrating a remote code execution vulnerability in the Jakarta Faces…

Technical analysis of CVE-2026-33701, an unsafe deserialization vulnerability in OpenTelemetry Java Agent RMI instrumentation, including exploit…

Here is a simple but effective exploit for CVE-2025-29927.

Proof-of-concept exploit for CVE-2026-21440, a critical path traversal in AdonisJS multipart uploads enabling arbitrary file write and remote code…


Jok3r v3 BETA 2 - Network and Web Pentest Automation Framework

Framework for Man-In-The-Middle attacks

The Browser Exploitation Framework Project

Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

Advanced CVE-2023-44487 HTTP/2 Rapid Reset vulnerability exploitation framework. Features multi-connection concurrent attacks, adaptive rate control,…

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that…