
CVE-2025-4094-POC
WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

Decrypts weak encrypted passwords from Argus Surveillance DVR systems via CVE-2022-25012, reconstructing plaintext credentials from DVRParams.ini…

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…


bypass all stages of the password reset flow

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

Hook PasswordChangeNotify

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

Exploit for CVE-2024-48322 targeting RunCodes instances. Retrieves user passwords via email inbox after authentication bypass, requiring only any…

Owa Valid Login Checker

SEt framework

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, recovering user credentials from weakly encrypted…

Prepostseo Login Checker

Scripts to test and exploit the Zerologon vulnerability (CVE-2020-1472) in Active Directory, enabling password reset and hash dumping of domain…

This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).

Proof-of-concept exploit for CVE-2024-10508: unauthenticated privilege escalation via password recovery bypass in RegistrationMagic WordPress plugin…