
CVE-2025-24799
Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…

Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…

Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

Manage BitLocker recovery keys, monitor drive encryption status, and unlock volumes through a portable interface for Windows.

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files

CVE-2023-38035 Recon oriented exploit, extract company name contact information

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to…

This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL…



HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Extract Windows credentials directly from VM memory snapshots and virtual disks


High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…