This is your work, valued
wpprobe. A fast WordPress plugin enumeration tool
931CVE-2023-29357. Microsoft SharePoint Server Elevation of Privilege Vulnerability
238CVE-2024-25600. Unauthenticated Remote Code Execution – Bricks <= 1.9.6
180CVE-2023-22515. CVE-2023-22515: Confluence Broken Access Control Exploit
154CVE-2024-45519. Zimbra - Remote Command Execution (CVE-2024-45519)
139CVE-2024-3273. D-Link NAS CVE-2024-3273 Exploit Tool
101CVE-2024-36401. GeoServer Remote Code Execution
89CVE-2023-6553. Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
86CVE-2023-4966. Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.
79pwncat-vl. Fancy reverse and bind shell handler
62CVE-2024-21887. A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
58CVE-2024-34102. CosmicSting (CVE-2024-34102)
48CVE-2024-56145. Unauthenticated RCE on CraftCMS when PHP `register_argc_argv` config setting is enabled
48CVE-2024-9474. PAN-OS auth bypass + RCE
45CVE-2024-8504. VICIdial Unauthenticated SQLi to RCE Exploit (CVE-2024-8503 and CVE-2024-8504)
44LFIHunt. Advanced Tool To Scan And Exploit Local File Inclusion (LFI) Vulnerabilities
41CVE-2024-27198. Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4
36CVE-2024-4577. PHP CGI Argument Injection vulnerability
35CVE-2024-21893-to-CVE-2024-21887. CVE-2024-21893 to CVE-2024-21887 Exploit Toolkit
27LeakPy. ☁️ LeakIX API Client (Unofficial)
23CVE-2024-1212. Unauthenticated Command Injection In Progress Kemp LoadMaster
20CVE-2024-29269. An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.
17msf-exploit-collection. ✪ Collection of Metasploit Modules ✪
17CVE-2023-50917. MajorDoMo Unauthenticated RCE: Deep Dive & Exploitation Techniques
16CVE-2024-8517. SPIP BigUp Plugin Unauthenticated RCE
16CVE-2024-3400. Python
15CVE-2023-46805. Ivanti Pulse Secure CVE-2023-46805 Scanner - Based on Assetnote's Research
14CVE-2023-30943. A Python-based tool to detect the CVE-2023-30943 vulnerability in Moodle, which allows unauthorized folder creation via specially crafted requests in TinyMCE loaders.
14CVE-2024-7954. Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
13CVE-2024-8672. Widget Options – The #1 WordPress Widget & Block Control Plugin <= 4.0.7 - Authenticated (Contributor+) Remote Code Execution
13CVE-2023-51467. Apache OfBiz Auth Bypass Scanner for CVE-2023-51467
12Ghost-Framework. Modified Version of Ghost Framework
12CVE-2023-5360. Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: CVE-2023-5360.
10CVE-2025-32432. CraftCMS RCE Checker (CVE-2025-32432)
10CVE-2024-20767. Exploit Toolkit for Adobe ColdFusion CVE-2024-20767 Vulnerability
10CVE-2023-22527. Atlassian Confluence - Remote Code Execution
9CVE-2024-5084. Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
9CVE-2024-22899-to-22903-ExploitChain. Comprehensive Exploit Chain for Multiple Vulnerabilities in VinChin Backup & Recovery <= 7.2
8CVE-2023-27372. SPIP Vulnerability Scanner - CVE-2023-27372 Detector
8CVE-2022-40684. Fortinet Critical Authentication Bypass Vulnerability (CVE-2022-40684) [ Mass Exploit ]
7CVE-2017-9841. PHPUnit RCE
7CVE-2025-5777. CitrixBleed 2 (CVE-2025-5777)
7CyberPanel. CyberPanel v2.3.6 Pre-Auth RCE Exploit Tool
7CVE-2023-35885. CloudPanel 2 Remote Code Execution Exploit
6CVE-2023-36846. Remote Code Execution on Junos OS CVE-2023-36846
5CVE-2023-1698. WAGO Remote Exploit Tool for CVE-2023-1698
5CVE-2024-31819. Unauthenticated Remote Code Execution (RCE) Vulnerability in WWBNIndex Plugin of AVideo Platform from 12.4 to 14.2
5CVE-2025-34152. Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)
5CVE-2023-3519. Citrix ADC RCE CVE-2023-3519
5CVE-2022-29464. Python script to exploit CVE-2022-29464 (mass mode)
5PersonalRobloxScripts. Here is my personal exploits
4CVE-2023-43208-EXPLOIT. A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)
4CVE-2022-29303. Python script to exploit CVE-2022-29303
3CTF-Challenges. This repo contains challenges I made to train my friends
3lfi-training. LFI Challenge - Capture The Flag (CTF)
2ssl_explorer. A CLI Tool for Extracting Server Ownership Clues from SSL/TLS Certificates
2poc. poc
2CVE-2022-1388. CVE-2022-1388 | F5 - Big IP Pre Auth RCE via '/mgmt/tm/util/bash' endpoint
1