
CVE_2020_35848
CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This…
Password cracking, brute-force, wordlists, and credential testing tools.

CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This…

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…


Hicip IP admin password reset script using CVE-2020-9529. This is made for educational purposes only of course.

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to > store authentication data


An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

0day discover CVE-2025-1738

Strapi Framework, 3.0.0-beta.17.4

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

Python Code for Exploit Automation CVE-2023-7028

HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager…

Bludit 3.9.2 auth bruteforce bypass



CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).