CVE-2021-3129. Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)
148DitherMe. DitherMe creates Watch Dogs 2 DedSec-style dithered images and GIFs, replicating the iconic glitchy hacker aesthetic
22CMS-Detector. A lightweight fast Go script to detect which CMS or framework a given website is running, based on HTTP response fingerprints.
6CVE-2026-25643. CVE-2026-25643: Frigate ≤0.16.3 Blind RCE via go2rtc exec injection
6Python-PGP. Simple Python script for encrypting/decrypting PGP messages
4CVE-2026-3891. Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload (CVE-2026-3891) PoC
4CVE-2025-14847. CVE-2025-14847 (MongoBleed)
3Onion-V3-Generator. A super simple and small Python script for generating .onion V3 domains for Tor services.
2G-Dorker. A Python3 script to automate Google search requests
2PGPBox-js. A user-friendly PGP Web GUI for generating, encrypting, signing, verifying, and decrypting PGP messages. Secure your communications effortlessly with this web-based GitHub hosted application.
2Tor-Wordpress-IP-Leaker. This is a Python script for using the WordPress XMLRPC pingback function to leak an IP address from a Tor domain
1CVE-2022-30190. Microsoft Support Diagnostic Tool (CVE-2022-30190)
1CVE-2026-2991. PoC exploit for CVE-2026-2991 — authentication bypass in KiviCare WordPress plugin (≤4.1.2) allowing unauthenticated patient account takeover and admin session extraction.
1cve-2024-56348. CVE-2024-56348 — JetBrains TeamCity <2024.12 auth bypass + RCE exploit (unauthenticated SYSTEM_ADMIN + shell)
1CVE-2025-69985. CVE-2025-69985: FUXA ≤1.2.8 Auth Bypass + RCE via /api/runscript
1cve-2025-66398. CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC
1cve-2025-32433. Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.
1CVE-2026-44262. Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.
1