
CVE-2026-18963
Detection and verification tool for CVE-2026-18963, a Keycloak reset-credentials state bypass. Performs version fingerprinting, realm/client/user…

Detection and verification tool for CVE-2026-18963, a Keycloak reset-credentials state bypass. Performs version fingerprinting, realm/client/user…

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

Proof-of-concept for CVE-2025-25749 demonstrating weak password policy in HotelDruid 3.0.7, with automated test scripts and mitigation…

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication…

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker…

Pass the Hash to a named pipe for token Impersonation

This is the exploit of CVE-2019-17240.

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…


automated password spraying tool

PoC Exploit for CVE-2018-8820

Kerberos RC4 deprecation: detection, remediation and guidance (CVE-2026-20833)

A tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service.

Enumerate valid users within Microsoft Teams and OneDrive with clean output.

enject: Hide .env secrets from prAIng eyes: secrets live in local encrypted stores (per project) and are injected directly into apps at runtime,…

Tool to remotely dump secrets from the Windows registry

A Powershell implementation of PrivExchange designed to run under the current user's context