
woo
Exploit woocommerce SQLI and grab user and password hash

Exploit woocommerce SQLI and grab user and password hash

3 linux kernel bugs chains to do secure comm app using side channel to establish key and establish covert channe;

FOGProject Authentication bypass CVE-2025-58443 Exploit

Exploit script for CVE-2025-24071 that leaks NTLM hashes from Windows by extracting a crafted ZIP/RAR file, exploiting .library-ms file handling.…

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

A simple utility to convert EXE files to JPEG images and vice versa.

This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity…

Reuse open handles to dynamically dump LSASS.

Bypassing NTFS permissions to read any files as unprivileged user.

PoC for CVE-2021-36934, which enables a standard user to be able to retrieve the SAM, Security, and Software Registry hives in Windows 10 version…

A Proof-of-Concept using Cache Smuggling + Exif data to passively download a second stage payload

ActionScript Proof of Concept to perform cross-domain reads

Proof of concept code to exploit CVE-2020-12116: Unauthenticated arbitrary file read on ManageEngine OpManger.

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

A path traversal in smbserver.py allows an attacker to read/write arbitrary files on the server.

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4

Python implementation/PoC for CVE-2024-40422. Exploits a critical directory traversal vulnerability in Devika v1's /api/get-browser-snapshot endpoint…