
CVE-2025-52488
This exploit targets a vulnerability in DNN (formerly DotNetNuke) versions 6.0.0 to before 10.0.1 that allows attackers to disclose NTLM hashes…

This exploit targets a vulnerability in DNN (formerly DotNetNuke) versions 6.0.0 to before 10.0.1 that allows attackers to disclose NTLM hashes…

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

ARMember Premium <= 7.3.1 Full Admin Account Takeover

CVE-2026-32488

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

Account takeover full PoC for CVE-2026-27886 in Strapi CMS


Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability

Atlassian Confluence Server and Data Center: CVE-2022-26138

IBM Lotus Domino <= R8 Password Hash Extraction Exploit

Exploit for CVE-2019-17662 (ThinVNC 1.0b1)

This is a exp of CVE-2018-15473

A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132

CVE-2018-13379 mass exploiter for Fortinet FortiOS SSL VPN. Extracts credentials instantly, saves to CSV + PostgreSQL. Multi-threaded, no bullshit…

Modern Joomla Auth-attack Toolkit J3 / J4 / J5 - CVE-2023-23752 · CVE-2023-23755 · CVE-2025-25227

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

Some Assmann manufactured IP-Cams leak the administrator password in their backup.

An unauthenticated data extraction vulnerability in Kyocera printers, which allows for recovery of cleartext address book and domain joined passwords.