


WPBF - a multithreaded WP brute forcer

Exploitability PoC for CVE-2026-43515 (Apache Tomcat constraint bypass).

Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter

listmonk’s Session Persistence After Password Reset and Password Change

Prepostseo Login Checker

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1


HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

Grafana Bruteforce tool


Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker…

tool for requesting Entra ID's P2P certificate and authenticating to a remote Entra joinned devices with it