
ZackAttack
Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!

Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!



CVE-2020-10130 - SearchBlox Product before V-9.1 is vulnerable to Business logic bypass

CVE-2025-0364: BigAnt Server RCE Exploit

Exploit script for SAP Business Objects SSRF

Metabase Pre-auth RCE (CVE-2023-38646)

Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases

Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases

WordPress Simple Business Directory Pro Plugin < 15.6.9 is vulnerable to a high priority Privilege Escalation

This is a Proof of Concept (PoC) script for exploiting Metabase, an open-source business intelligence and data analytics tool.

CVE Reproduction: cve-2025-61882-oracle_ebs_rce_reproduction

Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization

[CVE-2020-6286] SAP NetWeaver AS JAVA (LM Configuration Wizard) Directory Traversal

CVE-2026-46817

Mass CVE-2023-2744

CVE-2024-4443 Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an…