
CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability
Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

POC of CVE-2026-51031 for arbitrary local file read

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

CVE-2026-72550 — Friendica Unauthenticated Stacked-Query SQL Injection PoC (CVSS 9.8 Critical)



Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code…


Reuse open handles to dynamically dump LSASS.

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions

PowerSploit - A PowerShell Post-Exploitation Framework

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications

C# Tool to interact with MS Exchange based on MS docs

A standalone Blind XSS Script.

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)