
Chrome-App-Bound-Encryption-Decryption
Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

Exploits vulnerabilities in popular IP cameras (CCTV, GoAhead, Netwave) to disclose admin passwords. Supports single targets, file-based lists, and…

Exploits known vulnerabilities in popular routers (D-Link, Zyxel, TP-Link, Cisco, Huawei) to extract admin credentials, with support for single…

Ruby-based LDAP enumeration tool for internal penetration tests. Automates user, computer, and group discovery, password spraying, LAPS retrieval,…

Proof-of-concept exploit and detailed writeup for CVE-2020-15906, an authentication bypass in Tiki Wiki CMS Groupware 16.x-21.1 allowing…

Proof-of-concept exploit for CVE-2024-28000, a privilege escalation vulnerability in LiteSpeed Cache WordPress plugin, allowing unauthenticated…

Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.

Let's Snatch The Admin Panel Of Any Website In Seconds.

Python exploit for CVE-2020-1472 (Zerologon) that checks, exploits, and restores domain controller machine account passwords, enabling DCSync and…

Exploit script for CVE-2025-49132 that retrieves database credentials from vulnerable Pterodactyl panels via unauthenticated arbitrary file read,…

Proof-of-concept exploit for CVE-2021-36394 in Moodle, enabling admin password takeover and remote code execution via custom PHP functions.

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

Python exploit for CVE-2025-47227 targeting ScriptCase pre-authentication password reset vulnerability (CVSS 9.8) to gain unauthorized admin access.

Multithreaded WordPress brute-force tool that tests admin credentials against a list of sites using configurable threads, timeouts, and verbose…

Exploit for JumpServer CVE-2023-42820 that resets admin password and chains with CVE-2023-42819 to achieve remote code execution on affected versions.

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

Automated PoC exploit for CVE-2026-27886 in Strapi CMS. Performs email enumeration, password reset token exfiltration, and full admin account…

Fast WordPress default credential checker: uses common username/password pairs to detect weak admin accounts.