
CVE-2020-2733
Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

This Bash script checks domains for DNS zone transfer misconfigurations (CVE-1999-0532). It queries name servers and attempts AXFR requests; if…

BeHat Configuration file leaking

Appspec YML and YAML leaks

This tool is used to find php info page

CasaOS expose multiple unauthenticated API endpoints that allow remote disclosure of sensitive configuration files and system debug information

The WP Page Permalink Extension plugin (<= 1.5.4) allows authenticated users with insufficient privileges to trigger the AJAX action…

Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner

g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.

Disclosure for CVE-2025-9196

PoC exploit for CVE-2023-5142 targeting H3C GR series routers with an unauthenticated directory traversal vulnerability to extract sensitive…

Research framework redefining post-exploitation through decision intelligence.

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

[Reserved for CVE-2022-30006]

IBM i Access Client Solution < 1.1.9.4 - Local server broken access control.