Helios. Helios: Automated XSS Testing
158SquatSquasher. Discovering Typo Squatting on your domains!
86CVE-2024-32640-SQLI-MuraCMS. CVE-2024-32640 | Automated SQLi Exploitation PoC
78CVE-2024-4040-SSTI-LFI-PoC. CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support
65RCity-CVE-2024-27198. CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information
36CVE-2024-28995. CVE-2024-28955 Exploitation PoC
34GitHush. Detecting leaked secrets, API keys, credentials, and sensitive files from public repositories in near real-time using the GitHub Events API
34CVE-2024-29895-CactiRCE-PoC. CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds
23CVE-2024-31848-PoC. PoC for Exploiting CVE-2024-31848/49/50/51 - File Path Traversal
18Offensive-Security-Checklist.
13DoomBox. Easy OWASP Inspired CTF | Web 2 Root
7SGLang-0.5.9-RCE. Proof of Concept exploitation of CVE-2026-5760 - RCE in SGLang 0.5.9 via malicious GGUF
5EvasionHubCLI. EvasionHub API Wrapper | https://evasionhub.com
3StuubTube. Chrome extension dealing with YouTube ads without breaking ToS
3CVE-2025-3969-Exploit. CVE-2025-3969: Exploit PoC (OS CMD injection, Web Shell, Interactive Shell)
2stuubdev. Slightly outdated source for my portfolio
2Northumbria-Certificate-Fixer. A small bash script to update outdated GPG certificates, also imports and assigns University certificate.
2Appsmith-1.98-Stored-XSS-Exploit. Automating the exploitation of CVE-2026-7299 - Stored XSS via Database Table/Column Names in SQL Autocomplete within Appsmith =>1.99. Initial discovery 30/03/26
2Sticky. AI Powered Privilege Escalation!
1AC-Internal. Internal dynamic link library for Assault Cube. Current features access playerentity objects and write to their relative static addresses for modification to health, current weapon ammo, rapidfire, recoil, grenades. Future improvements to be added.
1Repo.
1