
EvilAbigail
Automated Linux evil maid attack

Automated Linux evil maid attack

CVE-2023-24055 PoC (KeePass 2.5x)

This vulnerability allows an attacker to bypass the credentials brute-force prevention mechanism of the Embedded Web Server (interface) of more than…

A vulnerability can allow an attacker to guess the automatically generated development mode secret token.

An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

bypass all stages of the password reset flow

CVE-2020-25749

Suka suka lah


An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

lib/G/functions.php in Chevereto 1.0.0 through 1.1.4 Free, and through 3.13.5 Core, allows an attacker to perform bruteforce attacks without…