This module exploits a SQL injection vulnerability in openDCIM's install.php endpoint CVE-2026-28515 to achieve remote code execution. The install....
This module establishes persistence through a BITS job that downloads and executes a payload. Background Intelligent Transfer Service BITS is a Win...
This module establishes persistence by modifying a PowerShell profile script, which is automatically executed when PowerShell starts. The module su...
Selenium Grid and Selenoid expose a WebDriver API that allows creating browser sessions with arbitrary capabilities. When deployed without authenti...
AVideo use auxiliary/gather/avideocatnamesqli msf auxiliaryavideocatnamesqli show actions ...actions... msf auxiliaryavideocatnamesqli set ACTION m...
This module will register a payload to run via the Active Setup mechanism in Windows. Active Setup is a Windows feature that runs once per user at ...
This module exploits an unauthenticated arbitrary file upload vulnerability in the StoryChief WordPress plugin use exploit/multi/http/wppluginstory...
This module adds a lisp based malicious extension to the emacs configuration file. When emacs is opened, the extension will be loaded and the paylo...
This module will install a payload that is executed during user logon. It writes a payload executable to disk and modifies the Userinit registry va...
This module exploits CVE-2026-21858, a critical unauthenticated remote code execution vulnerability in n8n workflow automation platform versions 1....
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.