
qyvora-toha3ee
Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

CVE-2019-9729. Transferred from https://github.com/DoubleLabyrinth/SdoKeyCrypt-sys-local-privilege-elevation

Docker-based XSS exploit for CVE-2020-7934 targeting Liferay portal. Demonstrates stored cross-site scripting via user profile fields to steal admin…

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

Stored XSS proof-of-concept for PHPGURUKUL Online Birth Certificate System v1.0, demonstrating authenticated JavaScript injection via profile name…

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

Brute-force attack tool against WPS registrar PINs to recover WPA/WPA2 passphrases, supporting online brute force and offline Pixie Dust attacks on…

CVE-2021-42666 - SQL Injection vulnerability in the Engineers online portal system.

a Fedora remix focused on pentesting and purple hat tooling

CVE-2026-77276 pre-auth macro RCE via convert-to on Collabora Online

Documentation and proof of concept code for CVE-2022-24125 and CVE-2022-24126.

CVE-2021-42667 - SQL Injection vulnerability in the Online event booking and reservation system.

Offensive Software Exploitation Course

Uses Shodan API to pull down C2 servers to run known exploits on them.

Exploit For SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)

Proof-of-concept demonstrating time-based SQL injection in Itsourcecode Online Furniture Shopping Project 1.0 via the id parameter in orderview1.php,…

SQL Injection in Online Shopping System Advanced (CVE-2025-51970)