
CVE-2022-23046
Proof-of-concept exploit for CVE-2022-23046, an authenticated SQL injection in PhpIPAM v1.4.4. Extracts server info, SMTP settings, user hashes, and…

Proof-of-concept exploit for CVE-2022-23046, an authenticated SQL injection in PhpIPAM v1.4.4. Extracts server info, SMTP settings, user hashes, and…

DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

Exploit script for CVE-2025-24071 that leaks NTLM hashes from Windows by extracting a crafted ZIP/RAR file, exploiting .library-ms file handling.…

Proof-of-concept for CVE-2022-45599: PHP type juggling vulnerability in Aztech WMB250AC router login.php allowing admin authentication bypass via…

After using the KeePass password dumper maybe some character parsed as ● is incorrect and you want to know the real character

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

Hidden AP with Deterministic Credentials


Proof-of-concept decrypting Araxis Merge's DPAPI-protected server credentials (CVE-2026-92680), demonstrating insufficiently protected credential…

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

A simple implementation/code smash of a bunch of other repos

Exploit for CVE-2025-2011

CVE-2023-23397 C# PoC

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)


cve-2020-1472 复现利用及其exp

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)