
CVE-2025-25198-PoC
PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

CVE-2025-58434 Proof of Concept


listmonk’s Session Persistence After Password Reset and Password Change


Security Research

This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

RomBuster is a router exploitation tool that allows to disclosure network router admin password.

CamOver is a camera exploitation tool that allows to disclosure network camera admin password.



Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.

cve-2023-22515的python利用脚本

CVE-2019-9053 Exploit for Python 3

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

Tools for Pentesting