
CVE-2026-52200
Security advisory detailing broken access control in UZ801/ES-U3TS MifiService web API, allowing unauthenticated data extraction, config…

Security advisory detailing broken access control in UZ801/ES-U3TS MifiService web API, allowing unauthenticated data extraction, config…

Proof-of-concept exploit for CVE-2026-42281, an unauthenticated SSRF in MagicMirror² ≤ 2.35.0, enabling config exfiltration, cloud metadata probing,…

Latency x-ray for undocumented hardware

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Automated Cisco SNMP Enumeration, Brute Force, Configuration Download and Password Cracking

BeHat Configuration file leaking

Multiple exploits for Monitorr

Automated data harvesting tool for extracting sensitive information (backups, clones, address books) from web servers via targeted scanning and…

PowerShell script to dump Microsoft Defender Config, protection history and Exploit Guard Protection History (no admin privileges required )

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

H3C ER8300G2-X config download

Bits generated while analyzing CVE-2019-6340 Drupal RESTful RCE

Bulk vulnerability scanner for CVE-2023-23752 that extracts configuration data from vulnerable Joomla instances.

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

Turn any collection of documents into a knowledge graph. Extract entities and relationships via LLM, deduplicate with your approval. Map domains,…

Authentication bypass exploit for Joomla CVE-2023-23752 that leaks administrator credentials and MySQL configuration from vulnerable versions…

Proof-of-concept exploit for path traversal in MasaCMS 7.2.1 via /index.cfm/_api/asset/image/, allowing unauthenticated attackers to read arbitrary…

Exploits Apache RocketMQ brokers vulnerable to CVE-2023-33246 remote code execution and checks targets via IP, CIDR, or file input.