| CVE-2017-5343 | Wordpress SQL Injection | [POC] |
| CVE-2018-8880 | Unauthenticated Lutron Quantum Bacnet v2 network info exfiltration | POC |
| CVE-2018-11629 | Default and unremovable credentials in Homeworks QS Lutron integration protocol. | POC |
| CVE-2018-11653 | Unauthenticated Netwave Camera information disclosure via network chipset data. | POC |
| CVE-2018-11654 | Unauthenticated Netwave Camera information disclosure. Check vulnerable hosts to CVE-2018-11653 | POC |
| CVE-2018-11681 | Default and unremovable credentials in Radio RA 2 Lutron integration protocol. | POC |
| CVE-2018-11682 | Default and unremovable credentials in Stanza Lutron integration protocol. | POC |
| CVE-2018-12634 | CirCarLife Scada < v4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI. | POC |
| CVE-2018-16668 | CirCarLife Scada < v4.3 internal installation path disclosure. | POC |
| CVE-2018-16669 | Due to a clear-text stored credentials, an unprivileged user can gain access to other services with higher privileges exploiting a flaw on Open Charge Point Protocol web implementation. All versions prior to <1.5.0 are vulnerable. | POC |