
CVE-2024-10924-Bypass-MFA-Wordpress-LAB
Lab environment and exploit script for CVE-2024-10924, demonstrating MFA bypass in WordPress via the Really Simple SSL plugin's skip_onboarding…

Lab environment and exploit script for CVE-2024-10924, demonstrating MFA bypass in WordPress via the Really Simple SSL plugin's skip_onboarding…

CVE-2021-29441 - Nacos Authentication Bypass

Enumerate information from NTLM authentication enabled web endpoints 🔎

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

Dominate Active Directory with PowerShell.

WireBug is a toolset for Voice-over-IP penetration testing

NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js

LEMPO (Ldap Exposure on POrtainer) is an exploit for CVE-2018-19466 (LDAP Credentials Disclosure on Portainer). Featured @ DevFest Siberia 2018

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

Mikrotik 0day Credential Disclosure Scanner

Vulnerability details and exploit for CVE-2021-3754

This script helps to pass through the captive portals in public Wi-Fi networks. It hijacks IP and MAC from somebody who is already connected and…

SSH man-in-the-middle tool

A little tool to play with Windows security

A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

An authentication bypass using an alternate path or channel in Fortinet product

cobaltstrike4.5版本破解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等

Exploit for CVE-2021-27342 vulnerability (telnet authentication brute-force protection bypass)