This module exploits a SQL injection vulnerability in openDCIM's install.php endpoint CVE-2026-28515 to achieve remote code execution. The install....
This module establishes persistence by modifying a PowerShell profile script, which is automatically executed when PowerShell starts. The module su...
Selenium Grid and Selenoid expose a WebDriver API that allows creating browser sessions with arbitrary capabilities. When deployed without authenti...
AVideo use auxiliary/gather/avideocatnamesqli msf auxiliaryavideocatnamesqli show actions ...actions... msf auxiliaryavideocatnamesqli set ACTION m...
This module will register a payload to run via the Active Setup mechanism in Windows. Active Setup is a Windows feature that runs once per user at ...
This module exploits an unauthenticated arbitrary file upload vulnerability in the StoryChief WordPress plugin use exploit/multi/http/wppluginstory...
This module adds a lisp based malicious extension to the emacs configuration file. When emacs is opened, the extension will be loaded and the paylo...
This module will install a payload that is executed during user logon. It writes a payload executable to disk and modifies the Userinit registry va...
This module exploits CVE-2026-21858, a critical unauthenticated remote code execution vulnerability in n8n workflow automation platform versions 1....
This module exploits an unauthenticated remote code execution vulnerability in the installation process of ChurchCRM versions 6.8.0 and earlier. By...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.