
CVE-2026-PSA-2026-00043-1
Proof-of-concept exploit for an unauthenticated root authentication bypass in Proxmox VE 7.0-8.0.3, intended for authorized security testing and…

Proof-of-concept exploit for an unauthenticated root authentication bypass in Proxmox VE 7.0-8.0.3, intended for authorized security testing and…

Offensive token-harvesting utility that searches x64 process memory and TokenBroker cache files for Azure AD/O365 JWT tokens across Office, Edge,…

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

CaptainCredz is a modular and discreet password-spraying tool.

CentOS Control Web Panel, Root Privilege Escalation

RCE for WingFTP v4.7.3

Technical breakdown of CVE-2026-34472, an auth bypass via leaked credentials affecting ZTE H188A routers.

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

Stealthy In-Memory Local Password Harvester (SILPH) tool: dump LSA, SAM and DCC2 with indirect syscall

Take security by obscurity to the next level (this is a bad idea, don't really use this please)

Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Enumerate information from NTLM authentication enabled web endpoints 🔎