
All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

Python PoC for CVE-2023-6063, an unauthenticated time-based blind SQL injection in WP Fastest Cache <=1.2.2, extracting WordPress password hashes and…

Tracking Copy Fail (CVE-2026-31431), the Linux algif_aead privilege escalation

Tracking Dirty Frag (CVE-2026-43284, CVE-2026-43500), the xfrm-ESP and RxRPC page-cache write LPE chain

Tracking the nginx CVE-2026-9256 rewrite-module heap overflow

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

There is a SQL injection vulnerability in the backend of Ruoyi v4.8.3

Proof-of-concept for CVE-2022-45782: predictable dotCMS password-reset tokens, with a token cracker and full exploit chain.

cve-2024-21413


Python exploit for CVE-2019-9053 SQL injection in CMS Made Simple 2.2.10 with password hash cracking and user enumeration capabilities.

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

Exploit for CVE-2025-2011

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

Automated SQL injection exploit for CVE-2022-24707 targeting Anuko Time Tracker 1.20.0. Extracts user credentials from tt_users database via…

This repo shows an exploit to CVE-2021-24762. This is an Blind SQLi exploit that, on default config, greps the admin password.

Python 3 exploit for CVE-2019-9053, an unauthenticated SQL injection in CMS Made Simple 2.2.9, that extracts admin credentials and optionally cracks…