
CVE-2025-65900
DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

Detection artifact generator that verifies BMC FootPrints instances for pre-authenticated RCE chain (CVE-2025-71257, CVE-2025-71260) by bypassing…

Exploit for CrushFTP SSTI vulnerability (CVE-2024-4040) enabling unauthenticated file read, authentication bypass, and remote code execution on…

eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Read

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication…

Mitel MiCollab Authentication Bypass to Arbitrary File Read


PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

Enumerate information from NTLM authentication enabled web endpoints 🔎

active directory query tool using LDAP Protocol , helps red teamer / penetration testers to validate users credentials , retrieve information about…

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

CVE-2020-27838 - KeyCloak - Information Exposure

CVE-2017-7921 is a critical vulnerability (CVSS score: 9.8) affecting multiple Hikvision IP camera and DVR models, first disclosed in 2017. It stems…

Proof-of-concept for CVE-2020-24029: unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A lightweight tool to quickly extract valuable information from the Active Directory environment for both attacking and defending.

Clone of w1.fi hostap.git - NOTE: This is not the main development location and pull requests for this repository are ignored. See the upstream…

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection…