
CVE-2024-4040-SSTI-LFI-PoC
CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

Portable OpenSSH

Offline, open-source web app for passkey-based file encryption and sharing. AES-256-GCM/HPKE, no cloud, no accounts; encrypt to recipients with…

Opens 1K+ IPs or Shodan search results and attempts to login

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

KeePass 2.53.1 with removed ECAS Trigger System Remediating CVE-2023-24055

A Beacon Object File suite for Microsoft SQL Server that speaks TDS 7.4 on the wire itself

Strelka Web UI for File Submission and Analysis

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

OAuth 2.0 client library for Kit applications supporting authorization code, PKCE, client credentials, and refresh token flows with built-in provider…

A command-line tool for securely backing up, restoring, and verifying secrets using interoperable standards like age encryption and coreutils,…

A proxy for net.tcp-based WCF traffic.

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

Patch for CVE-2024-10449: replaces vulnerable loginAction.php with a hardened version that requires database configuration for secure authentication.

Client-side browser extension providing AES-256-GCM encryption, X25519 key exchange, Ed25519 signatures, and zero-knowledge key management for secure…