
DVR-Exploiter
Bash script exploiting CVE-2018-9995 to extract credentials from vulnerable DVRs via web interface, supporting multiple DVR brands for automated…

Bash script exploiting CVE-2018-9995 to extract credentials from vulnerable DVRs via web interface, supporting multiple DVR brands for automated…

A flexible internet crawler used for scanning technologies, instances and vulnerabilities worldwide across the internet.

IoT Camera Reconnaissance and Live Viewer

Python-based proof-of-concept exploit for CVE-2018-14714, an RCE in ASUS routers, providing command execution and reverse shell capabilities for…

Proof-of-concept exploit for CVE-2024-7120 command injection vulnerability in RAISECOM gateway devices. Provides exploitation details, affected…

PoC exploit for CVE-2024-7029 in AVTech devices. Enables authentication bypass, remote code execution, vulnerability scanning, and interactive shell…

Python exploit for remote code execution on GPON home routers via CVE-2018-10562 authentication bypass and command injection. Targets exposed devices…

Exploit tool targeting Hikvision devices via CVE-2017-7921 and CVE-2021-36260 vulnerabilities for security testing and vulnerability verification.

Proof-of-concept for stored XSS vulnerability in Asus DSL-N14U router firmware, with exploit payloads and list of 70+ vulnerable ASP pages for…

India's first hacker e-learning platform offering courses in ethical hacking, penetration testing, IoT security, bug bounty, and mobile security with…

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

Open-source GPS tracking system supporting 200+ protocols and 2000+ device models. Provides real-time tracking, geofencing, driver monitoring, and…

Curated threat model examples for web/API, cloud, AI, IoT, and enterprise security, with practical approaches to identify and mitigate risks.

Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces…

Protocol analysis and Python client libraries for reverse-engineered oBike BLE/HTTP communications, including AES-encrypted REST payload decryption…

Detailed disclosure of CVE-2026-25197: Authorization bypass via IDOR in Gardyn Home Kit cloud API, exposing PII and camera images of 134K+ users…

CVE-2026-28767 disclosure: missing authentication on Gardyn Home Kit cloud API admin notifications endpoint, exposing internal system data and…

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…