
CVE-2021-36460
Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

Proof-of-concept for CVE-2022-45599: PHP type juggling vulnerability in Aztech WMB250AC router login.php allowing admin authentication bypass via…

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Web vulnerability scanner written in Python3

Windows-native penetration testing swiss army knife for lateral movement, credential access, data exfiltration, and vulnerability scanning across…

Web Application Vulnerability Scanner

Distributed Network Vulnerability Scanner

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Exploit script for CVE-2019-2618, a Weblogic arbitrary file upload vulnerability, with JSP webshell deployment and encrypted credential decryption.

New 0 day vulnerability allowing to leak NTLM hashes from browsers with one click

php-cli vulnerability scanner

Proof-of-concept exploit for CVE-2018-14847 (MikroTik WinBox vulnerability) enabling arbitrary file read and plaintext password extraction via TCP/IP…

This vulnerability allows an attacker to bypass the credentials brute-force prevention mechanism of the Embedded Web Server (interface) of more than…

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

InfluxDB CVE-2019-20933 vulnerability exploit

PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script