
commix
Automated All-in-One OS Command Injection Exploitation Tool

Automated All-in-One OS Command Injection Exploitation Tool

WooCommerce plugin: photo & video product reviews, closing CVE-2026-12684's unauthenticated-upload vulnerability class by construction

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

Working implementation: cryptographically verified short-lived identities for AI decision authentication — CVE-2025-59536 (Patent Pending US…

DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

CVE-2023-34468 Apache NiFi ExecuteSQL H2 RUNSCRIPT RCE PoC

JavaScript beacons and C2 to be used for XSS payload or post exploitation implants on webapp servers or desktop software to monitor users and…

Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

Short Python script for exploiting CVE-2025–24000 based on this blog post: https://medium.com/@security_56355/from-subscriber-to-admin-reproducing-cve…

Extract AutoIt scripts embedded in PE binaries

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

CVE-2025-53690 POC

Detailed advisory for CVE-2025-56219, a rate-limiting flaw in Ascertia SigningHub's Add User API, enabling automated user creation and denial of…

Probabilistic Context Free Grammar (PCFG) password guess generator

A short and sweet simple exploit script for the CVE-2012-2982 Authenticated RCE vulnerability in the /file/show.cgi/bin endpoint.


Th3Inspector 🕵️ Best Tool For Information Gathering 🔎