
VeeamDumper-BOF
A credential extraction BOF for Veeam Backup and Replication and Veeam One

A credential extraction BOF for Veeam Backup and Replication and Veeam One

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

cve-2016-16113

Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…

RomBuster is a router exploitation tool that allows to disclosure network router admin password.

CVE-2023-6875 exploit written for Xakep.Ru

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

CVE-2023-23397 PoC

A little tool to play with Kerberos.

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

Collection of VBA macro published in our twitter / blog

Strapi Framework, 3.0.0-beta.17.4

The LAZY script will make your life easier, and of course faster.
