
Magnohost-Vulnerabilities-pentest
Manual black-box penetration test of MagnoHost and MeteorCloud infrastructure, documenting exposed MariaDB, default credentials, CVE-2024-27102, and…

Manual black-box penetration test of MagnoHost and MeteorCloud infrastructure, documenting exposed MariaDB, default credentials, CVE-2024-27102, and…

Python PoC exploiting CVE-2026-27739 in Angular SSR: header injection via prototype pollution and SSRF chaining to AWS IMDS/GCP metadata for…

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

Batch vulnerability scanner that integrates FOFA to discover and test Apache APISIX Dashboard instances for CVE-2021-45232 unauthorized access.

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Validates and exploits VMware ESXi SFCB authentication bypass (CVE-2021-21994) via a probe/fuzz harness, enabling unauthenticated CIM-XML enumeration.

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Set of tools to audit SIP based VoIP Systems

CVE-2023-20052, information leak vulnerability in the DMG file parser of ClamAV

The simple PoC of CVE-2023-27587

CVE-2026-0740

CVE-2026-42945 Nginx Rift

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

Proof-of-concept exploit for CVE-2022-36163, a format string vulnerability in pdftoroff hovacui 1.1.0 PDF reader, demonstrating local…

Integer overflow in Oniguruma

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read