
CVE-2024-48887-Exploit
Unverified Password Change (CWE-620)

Unverified Password Change (CWE-620)

Demonstration of the WP Visitor Statistics plugin exploit

FOSSBilling CVE-2026-53647 & CVE-2026-53646 PoC — Unauthenticated API key disclosure & password reset token reuse

Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)

Brute-force attack tool against WPS registrar PINs to recover WPA/WPA2 passphrases, supporting online brute force and offline Pixie Dust attacks on…

Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy . Brutal is…

Crack any Microsoft Windows users password without any privilege (Guest account included)

A python tool to automate KeePass discovery and secret extraction.

A full-featured open-source Wi-Fi fuzzer

Use ESC1 to perform a makeshift DCSync and dump hashes

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)


cve-2020-1472 复现利用及其exp

XMLRPC server for password cracking

use the Apple CoreText exploit (CVE-2012-3716) and launch an AP to affect all devices within wifi range

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)