
Kimai-CVE-2026-49865-POC
PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

This repository documents the process of identifying, analyzing, and gathering Open Source Intelligence (OSINT) on a specific security vulnerability…

Identify vulnerable (RCE) vBulletin 5.0.0 - 5.5.4 instances using Shodan (CVE-2019-16759)

Red Team utilities for setting up CWP CentOS 7 payload & reverse shell (Red Team 9 - CW2023)

Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159) - https://ricardojoserf.github.io/CVE-2021-31159/

Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)

A Shodan hunter for CVE-2022-40140

pentest on MagnoHost hosting provider & MeteorCloud infrastructure with 15+ servers mapped. Findings: MariaDB exposed on 6 servers, OmniDialer…

Check a list of Pterodactyl panels for vulnerabilities from a file.

POC for CVE-2024-4577 with Shodan integration

This Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.

Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.

Get GeoLocation of Exploited Device using CVE-2024-31320& bluetooth

CiscoRV320Dump CVE-2019-1653 - Automatition.