
CVE-2025-3616
Metasploit module exploiting arbitrary file upload in Greenshift WordPress plugin (CVE-2025-3616) to achieve RCE via MIME spoofing, with…

Metasploit module exploiting arbitrary file upload in Greenshift WordPress plugin (CVE-2025-3616) to achieve RCE via MIME spoofing, with…

LDAP-based Active Directory privilege escalation framework supporting pass-the-hash, pass-the-ticket, and certificate authentication for automated…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

A little tool to play with Windows security

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

Automated Exploit Toolkit for CVE-2015-6095 and CVE-2016-0049


An authentication bypass using an alternate path or channel in Fortinet product

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

The most comprehensive authentication framework

Easy to use cryptographic framework for data protection: secure messaging with forward secrecy and secure data storage. Has unified APIs across 14…

Cross-platform framework for enumerating O365 accounts, password spraying, exfiltrating emails/Teams/OneDrive data, and backdooring EntraID accounts…

Serverless AITM Simulation Framework for Entra ID and M365

Kerberos-based password spraying framework for Active Directory with built-in lockout prevention, user enumeration integration, recursive password…

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

Vulnerability Research