
CVE-2022-22947
Python-based memory shell injection tool for CVE-2022-22947, supporting Spring, Netty, and Godzilla memory shells with simple CLI usage.

Python-based memory shell injection tool for CVE-2022-22947, supporting Spring, Netty, and Godzilla memory shells with simple CLI usage.

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

A simple tool to interact with web shells and command injection vulnerabilities

It is a simple tool to exploit local file include . vulnerabilities

Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.

This is a simple python tool to automatically deface webdav vulnerable websites.

Exploit tool for CVE-2022-1162 that enumerates GitLab users and performs authentication bypass via a crafted login request.

Human and machine readable web vulnerability testing format

Scans host lists for GeoServer endpoints vulnerable to CVE-2023-25157 SQL injection, verifies exposed paths with keyword checks, and logs confirmed…

Scanner and educational guide for CVE-2025-49844 (RediShell), a Redis Lua scripting use-after-free vulnerability. Checks Redis servers for exposure,…

Simple C# implementation of CVE-2017-8759

Bash and Node.js scripts to automate SQL injection exploitation against vulnerable web applications, targeting CVE-2024-7456.

Docker-based lab to validate CVE-2021-44228 (Log4Shell) in Java apps, test mitigations, and simulate RCE via LDAP and HTTP payloads.

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

Simple Backdoor Manager with Python (based on weevely)

Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.

CVE-2025-24813-POC JSP Web Shell Uploader

Remot3d: is a simple tool created for large pentesters as well as just for the pleasure of defacers to control server by backdoors