
EternalView
EternalView is an all in one basic information gathering and vulnerability assessment tool

EternalView is an all in one basic information gathering and vulnerability assessment tool

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound…

Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.

Exploit PoC of CVE-2026-6356


Traveller is an Easy Linux machine featuring a Joomla 4.2.7 travel booking website vulnerable to CVE-2023-23752, an unauthenticated REST API…

PoC code written for CVE-2022-0944 to make exploitation easier. Based on information found here: …

This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack.…

WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation




The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive…

An information disclosure vulnerability that could be exploited to read arbitrary files from a server when parsing an image in Image Magic.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Repo containing all info, scripts, etc. related to CVE-2021-44228

Chaining CVE-2021-26855 and CVE-2021-26857 to exploit Microsoft Exchange