
CVE-2026-66066
PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

PoC exploit for Rails Active Storage/libvips CVE-2026-66066: uses crafted MAT/HDF5 files for arbitrary file read, recovers secret_key_base, and…

Command-line aircraft OSINT tool for gathering tail numbers, ICAO codes, flight logs, and owner details from public aviation data sources, with PDF…

Proof-of-concept exploit for CVE-2014-0130, a Rails directory traversal vulnerability. Demonstrates path traversal payload and references HackerOne…

Interactive OAuth phishing toolkit for Office365 that performs token theft, email search/sending, file exfiltration, and document replacement via…

Proof-of-concept exploit for CVE-2019-5418, demonstrating file content disclosure on Ruby on Rails via crafted Accept headers, with a demo…

A lightweight aviation intelligence tool that queries ADSB-Exchange flight data using tail numbers or ICAO identifiers to quickly profile aircraft…

Proof-of-concept exploit for CVE-2025-56499, demonstrating arbitrary file read via missing path validation in mihomo's rule-provider configuration,…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

Python proof-of-concept for authenticated path traversal (CWE-22) in Camaleon CMS, enabling arbitrary file read via crafted requests to…

Get trails lib: Get all urls indexed of target

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

short view of ruby on rails properties misconfiguration

A simple Python script that reads a text file with lots of e-mails and passwords, and tries to check if those credentials are valid by trying to…

Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit

BookingPress < 1.0.11 - Unauthenticated SQL Injection