
XSSFire
A standalone Blind XSS Script.

A standalone Blind XSS Script.

PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…


AWS AMAZON S3 Bucket Takeover Scanner & Claim Tool

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

CVE-2026-21858

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…


MLflow LFI/RFI Vulnerability -CVE-2023-1177 - Reproduced

Oliver POS – A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

ARMember Premium <= 7.3.1 Full Admin Account Takeover

Account takeover full PoC for CVE-2026-27886 in Strapi CMS


RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
