
GetDataReport
Get information client with getdatareport (Plugin)

Get information client with getdatareport (Plugin)

Exploit script for CVE-2025-50946

Exploit script for CVE-2022-41544 - RCE in get-simple CMS

The Inspector tool is a privilege escalation helper (PoC), easy to deployed on web server, this tool can list process running with root, check kernel…

Pulse Secure VPN CVE-2019-11510

Python proof-of-concept for CVE-2021-44228 (Log4Shell) that automates exploitation via a crafted Java payload, with argparse options for customizable…

Batch exploit script for CVE-2021-21402 (Jellyfin arbitrary file read) that checks for path traversal vulnerability via GET requests to win.ini.

Proof-of-Concept (PoC) exploit script for the Directory Traversal vulnerability (CVE-2016-10924) found in the WordPress plugin ebook-download…

Auto Installer Script for Cuckoo Sandbox

Weaponized exploit script for CVE-2020-35575, a password-disclosure vulnerability in TP-Link router web interfaces, granting remote administrative…

Python exploit script for CVE-2023-2982, packaged in a Docker container for automated deployment and testing against vulnerable targets.

:orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report

This script allows for remote code execution (RCE) on Oracle WebLogic Server

a exp for cve-2018-9948/9958 , current shellcode called win-calc

Exploit for CVE-2020-15778(OpenSSH vul)

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

Local isolated reproduction lab for CVE-2026-35037, an unauthenticated SSRF vulnerability in Ech0's GET /api/website/title endpoint. Includes Docker…

Proof-of-concept for absolute path disclosure in Veno File Manager 4.4.9 via an unauthenticated GET request to a debug script, revealing the server's…