France

Valentin Lobstein

Elite
@Chocapikk

What I publish is the polite version.

wpprobe. A fast WordPress plugin enumeration tool

931

CVE-2023-29357. Microsoft SharePoint Server Elevation of Privilege Vulnerability

238

CVE-2024-25600. Unauthenticated Remote Code Execution – Bricks <= 1.9.6

180

CVE-2023-22515. CVE-2023-22515: Confluence Broken Access Control Exploit

154

CVE-2024-45519. Zimbra - Remote Command Execution (CVE-2024-45519)

139

CVE-2024-3273. D-Link NAS CVE-2024-3273 Exploit Tool

101

CVE-2024-36401. GeoServer Remote Code Execution

89

CVE-2023-6553. Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution

86

CVE-2023-4966. Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.

79

pwncat-vl. Fancy reverse and bind shell handler

62

CVE-2024-21887. A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

58

CVE-2024-34102. CosmicSting (CVE-2024-34102)

48

CVE-2024-56145. Unauthenticated RCE on CraftCMS when PHP `register_argc_argv` config setting is enabled

48

CVE-2024-9474. PAN-OS auth bypass + RCE

45

CVE-2024-8504. VICIdial Unauthenticated SQLi to RCE Exploit (CVE-2024-8503 and CVE-2024-8504)

44

LFIHunt. Advanced Tool To Scan And Exploit Local File Inclusion (LFI) Vulnerabilities

41

CVE-2024-27198. Proof of Concept for Authentication Bypass in JetBrains TeamCity Pre-2023.11.4

36

CVE-2024-4577. PHP CGI Argument Injection vulnerability

35

CVE-2024-21893-to-CVE-2024-21887. CVE-2024-21893 to CVE-2024-21887 Exploit Toolkit

27

LeakPy. ☁️ LeakIX API Client (Unofficial)

23

CVE-2024-1212. Unauthenticated Command Injection In Progress Kemp LoadMaster

20

CVE-2024-29269. An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

17

msf-exploit-collection. ✪ Collection of Metasploit Modules ✪

17

CVE-2023-50917. MajorDoMo Unauthenticated RCE: Deep Dive & Exploitation Techniques

16

CVE-2024-8517. SPIP BigUp Plugin Unauthenticated RCE

16

CVE-2024-3400. Python

15

CVE-2023-46805. Ivanti Pulse Secure CVE-2023-46805 Scanner - Based on Assetnote's Research

14

CVE-2023-30943. A Python-based tool to detect the CVE-2023-30943 vulnerability in Moodle, which allows unauthorized folder creation via specially crafted requests in TinyMCE loaders.

14

CVE-2024-7954. Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12

13

CVE-2024-8672. Widget Options – The #1 WordPress Widget & Block Control Plugin <= 4.0.7 - Authenticated (Contributor+) Remote Code Execution

13

CVE-2023-51467. Apache OfBiz Auth Bypass Scanner for CVE-2023-51467

12

Ghost-Framework. Modified Version of Ghost Framework

12

CVE-2023-5360. Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: CVE-2023-5360.

10

CVE-2025-32432. CraftCMS RCE Checker (CVE-2025-32432)

10

CVE-2024-20767. Exploit Toolkit for Adobe ColdFusion CVE-2024-20767 Vulnerability

10

CVE-2023-22527. Atlassian Confluence - Remote Code Execution

9

CVE-2024-5084. Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

9

CVE-2024-22899-to-22903-ExploitChain. Comprehensive Exploit Chain for Multiple Vulnerabilities in VinChin Backup & Recovery <= 7.2

8

CVE-2023-27372. SPIP Vulnerability Scanner - CVE-2023-27372 Detector

8

CVE-2022-40684. Fortinet Critical Authentication Bypass Vulnerability (CVE-2022-40684) [ Mass Exploit ]

7

CVE-2017-9841. PHPUnit RCE

7

CVE-2025-5777. CitrixBleed 2 (CVE-2025-5777)

7

CyberPanel. CyberPanel v2.3.6 Pre-Auth RCE Exploit Tool

7

CVE-2023-35885. CloudPanel 2 Remote Code Execution Exploit

6

CVE-2023-36846. Remote Code Execution on Junos OS CVE-2023-36846

5

CVE-2023-1698. WAGO Remote Exploit Tool for CVE-2023-1698

5

CVE-2024-31819. Unauthenticated Remote Code Execution (RCE) Vulnerability in WWBNIndex Plugin of AVideo Platform from 12.4 to 14.2

5

CVE-2025-34152. Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated RCE (CVE-2025-34152)

5

CVE-2023-3519. Citrix ADC RCE CVE-2023-3519

5

CVE-2022-29464. Python script to exploit CVE-2022-29464 (mass mode)

5

PersonalRobloxScripts. Here is my personal exploits

4

CVE-2023-43208-EXPLOIT. A PoC exploit for CVE-2023-43208 - Mirth Connect Remote Code Execution (RCE)

4

CVE-2022-29303. Python script to exploit CVE-2022-29303

3

CTF-Challenges. This repo contains challenges I made to train my friends

3

lfi-training. LFI Challenge - Capture The Flag (CTF)

2

ssl_explorer. A CLI Tool for Extracting Server Ownership Clues from SSL/TLS Certificates

2

poc. poc

2

CVE-2022-1388. CVE-2022-1388 | F5 - Big IP Pre Auth RCE via '/mgmt/tm/util/bash' endpoint

1
58
Apply