✪ Collection of Metasploit Modules ✪
☆17Apr 17, 2026Updated 3 months ago
Alternatives and similar repositories for msf-exploit-collection
Users that are interested in msf-exploit-collection are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Ivanti Pulse Secure CVE-2023-46805 Scanner - Based on Assetnote's Research☆14Jan 19, 2024Updated 2 years ago
- Windfall - Unauthenticated RCE exploit chain for Windmill & Nextcloud Flow (CVE-2026-29059). Path traversal + credential leak + PostgreSQ…☆18Apr 7, 2026Updated 4 months ago
- Simple python3 script to automate CVE-2018-9995☆11Feb 20, 2024Updated 2 years ago
- PoC for Exploiting CVE-2024-31848/49/50/51 - File Path Traversal☆18May 7, 2024Updated 2 years ago
- ☆15Apr 6, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Apache HugeGraph Server Unauthenticated RCE - CVE-2024-27348 Proof of concept Exploit☆19Jun 3, 2024Updated 2 years ago
- Widget Options – The #1 WordPress Widget & Block Control Plugin <= 4.0.7 - Authenticated (Contributor+) Remote Code Execution☆13Dec 2, 2024Updated last year
- ☆23Updated this week
- OpenSSH Vulnerabilities Scanner: Bulk Scanning Tool for 21 different OpenSSH CVEs.☆18Apr 29, 2025Updated last year
- PAN-OS auth bypass + RCE☆45Nov 19, 2024Updated last year
- # 🕵️ PathCatcher v1.0 - Path Traversal & LFI Scanner☆24Jul 13, 2025Updated last year
- The Shodan developer documentation covering the various APIs for Shodan, Exploits, Scanhub and anything else that's offered by Shodan.☆23Sep 16, 2013Updated 12 years ago
- A Python script to find tenant id an region from a list of domain names.☆22Jan 31, 2025Updated last year
- CipherRun is an ethical hacking tool used to execute shellcode easily while bypassing antivirus solutions.☆13Jan 30, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Exploit for the unauthenticated file upload vulnerability in WordPress's Royal Elementor Addons and Templates plugin (< 1.3.79). CVE-ID: …☆10Nov 2, 2023Updated 2 years ago
- CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)☆15Apr 18, 2026Updated 3 months ago
- Unauthenticated RCE on CraftCMS when PHP `register_argc_argv` config setting is enabled☆47Dec 23, 2024Updated last year
- PoC☆12Apr 7, 2025Updated last year
- POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.☆34Jul 4, 2024Updated 2 years ago
- Will attempt to retrieve DB details for FastAdmin instances☆68Aug 20, 2024Updated last year
- Unify your OAST provider management and consolidate all interactions into a single, streamlined workflow.☆26May 23, 2026Updated 2 months ago
- A Post-exploitation Toolset for Interacting with the Microsoft Graph API☆16Nov 16, 2023Updated 2 years ago
- Keycloak admin API allows low privilege users to use administrative functions☆31Oct 12, 2024Updated last year
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- A simple compiling of notes and information / teachings on how stegonography works, and how we can use stegonography to execute system co…☆11Feb 27, 2022Updated 4 years ago
- Red Teaming Tactics and Techniques☆13Feb 10, 2022Updated 4 years ago
- Jenkins Security Research or Hacking Jenkins ;)☆12Dec 10, 2024Updated last year
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆14Jul 9, 2023Updated 3 years ago
- ☆39Dec 14, 2024Updated last year
- A multifunctional Android RAT with GUI based Web Panel without port forwarding.☆12Dec 18, 2022Updated 3 years ago
- CVE-2025-53770 Mass Scanner☆15Jul 29, 2025Updated last year
- Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12☆13Aug 12, 2024Updated 2 years ago
- ☆11Aug 26, 2024Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Offensive V Programming☆18Nov 3, 2021Updated 4 years ago
- Framework for Man-In-The-Middle attacks☆15Feb 19, 2018Updated 8 years ago
- A VSCode-ium extension that speeds up DuckyScript development with ready-to-use snippets and fun ducky icons for a more efficient and enj…☆30Apr 2, 2026Updated 4 months ago
- Python Scanner and Exploiter of Remote File Inclusion Vulnerabilitie☆13Jan 6, 2022Updated 4 years ago
- programmatic control of the mouse☆16Jun 28, 2023Updated 3 years ago
- nmap detection scripts for CVE-2022-45477, CVE-2022-45479, CVE-2022-45482, CVE-2022-45481☆16Apr 19, 2024Updated 2 years ago
- Bug Bounty ultimate tool☆28Jun 28, 2026Updated last month