
CVE-2025-14177
PHP getimagesize() CVE-2025-14177 - Heap Memory Leak Exploit Generator Fully functional exploit chain in Python

PHP getimagesize() CVE-2025-14177 - Heap Memory Leak Exploit Generator Fully functional exploit chain in Python
Python exploit tool for CVE-2026-8451 Citrix Netscaler memory overread vulnerability. Generates detection artifacts by leaking memory from target…

Swiss army knife Webserver in Golang. Keep simple like the python SimpleHTTPServer but with many features

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

Single-file Python scanner for CVE-2026-48907 (Joomla JCE Editor RCE). Detects Joomla/JCE, performs intrusive math-verified payload test, supports…

Simple python script to check against hypothetical JWT vulnerability.

Reflected XSS proof-of-concept exploit for Jenkins build-metrics plugin CVE-2019-10475, with a Python weaponization script for generating malicious…

Python PoC exploiting CVE-2025-24813, an Apache Tomcat partial PUT deserialization RCE. Auto-detects vulnerable variants, supports blind command…

Python exploit for CVE-2025-32432, an unauthenticated RCE in Craft CMS via Yii2 __class injection, with command execution and reverse shell support.

Python PoC for CVE-2026-12793 in JetFormBuilder <= 3.6.2: unauthenticated privilege escalation leading to plugin upload and remote code execution,…

The CSRF Exploit Generator allows users to generate a CSRF exploit form with configurable parameters.

CVE-2023-1545-POC with python

Python exploit script for CVE-2018-1306 in Apache Pluto 3.0.0, enabling malicious file upload via HTTP method tampering to achieve remote code…

Python PoC for CVE-2022-44268 that embeds arbitrary file contents into PNG images via ImageMagick, with extraction support for exiftool.

Tool for detecting and exploiting CVE-2025-25257 in Fortinet FortiWeb.

The all-in-one browser extension for offensive security professionals 🛠


Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.