
unshackle
Open-source tool to bypass windows and linux passwords from bootable usb

Privacy-first password manager with local storage and bring-your-own-cloud sync across Google Drive, Microsoft OneDrive, and Dropbox. Your…

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Proof-of-concept exploit for Progress WhatsUp Gold SQL injection authentication bypass (CVE-2024-6670). Includes root cause analysis and automated…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Exploit for CVE-2025-47227 - ScriptCase Password Reset (Pre-Auth)

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password…

Password Strength Evaluator is a tool to evaluate the strength of passwords and provide recommendations to improve their security.

Proof-of-concept exploit for CVE-2024-10508: unauthenticated privilege escalation via password recovery bypass in RegistrationMagic WordPress plugin…

Proof-of-concept exploit for CVE-2017-8295, demonstrating unauthorized password reset in WordPress 4.7.4 by intercepting the reset link without prior…

CVE-2020-26061 - ClickStudios Passwordstate Password Reset Portal

Bypass for Symantec Endpoint Protection's Client User Interface Password

Modifed ver of the original exploit to save some times on password reseting for unprivileged user