
A-xex
This project is part of a school work focusing on network security.

This project is part of a school work focusing on network security.

OpenEMR < 5.0.2 - (Authenticated) Path Traversal - Local File Disclosure

VMWare-CVE-2021-21975 SSRF vulnerability

PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)

Async-based exploit tool for CVE-2025-5777 that detects and extracts leaked authentication tokens, internal IPs, and hidden endpoint paths from…

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3

CVE-2023-26083-Mali-InfoLeak-PoC

HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager…

CVE-2026-25197: Authorization Bypass via IDOR — Gardyn Home Kit (ICSA-26-055-03)

CVE-2025-51482 POC, Dump Credentials From zm.Users

Pre-auth Local File Inclusion in WP User Manager <= 2.9.17 via path traversal in tab parameter (CVSS 7.5)

Moodle 4.5.0-4.5.2 Unauthenticated REST API User Data Exposure via Stack Trace Args Leak | CVSS 7.5

Air-gapped cybersecurity assistant for security professionals. 100% offline AI-powered analysis tool for Nmap, Volatility, BloodHound, Metasploit,…

This Python script helps to detect the Etherleak (CVE-2003-0001) vulnerability on a target host by analyzing the padding data in network packets. The…

CVE-2026-22557 Path Traversal Ubiquti UniFi Network Application

A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public…

CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in…