
CVE-2022-42176
Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…

Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…

CVE-2021-3707 , CVE-2021-3708

Detailed writeup and step-by-step proof-of-concept for CVE-2020-11107, a Windows XAMPP privilege escalation vulnerability allowing arbitrary command…

Public OCI-Image (docker image) Security Checker

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific…

Curated catalog of AWS resource types that can be publicly exposed, with CLI commands for creating and auditing public access configurations across…

One command grades your whole cloud account — misconfigurations, missing observability, and security posture.

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices.…

CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

BeHat Configuration file leaking

Appspec YML and YAML leaks

This tool is used to find php info page

CGI Print ENV leaking