


POC Exploit for CVE-2021-31630 written in Python3 and using C reverse shell with non-blocking mode

A script to Fuzz and and exploit Apache struts CVE-2017-9805


:zap: Worlds fastest steghide cracker, chewing through millions of passwords per second :zap:

The ultimate steganography and digital forensics toolkit. Hide and extract data across images, audio, video, documents, and network packets, or run…

A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.

A tool to dump users's .plist on a Mac OS system and to convert them into a crackable hash


CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

Steganography brute-force utility to uncover hidden data inside files