
sccm-http-looter
Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)


ActionScript Proof of Concept to perform cross-domain reads

WP SuperBackup <= 2.3.3 - Missing Authorization to Unauthenticated Back-Up File Download

Proof-of-concept for CVE-2025-25279: path traversal in Mattermost Boards allows arbitrary file read via crafted import archive and board duplication.

Exploiting misconfigured firebase databases

Proof-of-concept for CVE-2021-27187: cleartext credential storage in FX Aggregator terminal client login.sav file, enabling local credential theft…

trellix DLP Bypass

Content hijacking proof-of-concept using Flash, PDF and Silverlight

An anonymizer tool for replacing PII and similar data in dev/test databases copied from production

CVE-2023-28432 MinIO敏感信息泄露检测脚本

CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion

CVE-2025-10681: Hardcoded Azure Blob Storage Account Key — Gardyn Home Kit (ICSA-26-055-03)

Event monster <= 1.4.3 - Information Exposure Via Visitors List Export

Scans ServiceNow instances for widget-simple-list plugin misconfigurations that expose data via the API, supporting single URLs, URL lists,…