
CVE-2025-2304
Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.

Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.

BlackVue DR750 CVE CVE-2023-27746 CVE-2023-27747 CVE-2023-27748

An exploitation tool to extract passwords using CVE-2015-5995.

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

ZenoMinder Blind SQL Injection PoC

Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…

esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).

LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000

Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC

This is a Proof-Of-Concept of CVE-2025-63353

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario…