



TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

"Reverse engineering analysis of RedLine Stealer, a .NET-based info-stealer that uses C2 domains (198.46.86.63, tempuri.org), Windows Defender…

A proof of concept demonstrating the use of Google Drive for command and control.

Exploiting misconfigured firebase databases

This is a SMS And Call Bomber For Linux And Termux


Pivotable Reverse WhoIs / PDNS Fusion with Registrant Tracking & Alerting plus API for automated queries (JSON/CSV/TXT)

Grafana Unauthorized arbitrary file reading vulnerability

Two WinForms GUI tools for enumerating, searching, and exfiltrating data from M365 environments using application-level OAuth tokens



Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications

telegram bug that discloses user's hidden phone number (still unpatched) (exploit included)

An unauthenticated data extraction vulnerability in Kyocera printers, which allows for recovery of cleartext address book and domain joined passwords

VMware vCenter(Unauthenticated)