
CVE-2025-65427
Proof-of-concept exploit for CVE-2025-65427: missing rate limiting on Dbit N300 T1 Pro router login API enabling brute-force attacks and…

Proof-of-concept exploit for CVE-2025-65427: missing rate limiting on Dbit N300 T1 Pro router login API enabling brute-force attacks and…

Unauthenticated Privilege Escalation to Administrator via Role Form Field

It is the details of CVE-2025-45466

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

Kankun Smart Socket Hijacker and Sniffer. The kankun smart socket and its mobile app use a hardcoded AES 256 bit key to encrypt and decrypt…

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, recovering user credentials from weakly encrypted…

Username Enumeration in Trivision NC-227WF

Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)

Demonstrates a brute-force attack bypassing two-factor authentication in Nagios Fusion due to missing rate limiting and lockout, with CVE-2025-60424…

Proof-of-concept of vulnerability found in Totolink A720R router

Public Disclosure

PoC for CVE-2021-45041

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

PoC for CVE-2024-42049

Python 3 exploit for CVE-2019-9053 (SQL injection) with hash-cracking, updated from outdated Python 2 code for TryHackMe CTF use.

Proof-of-concept for CVE-2025-24071, demonstrating NTLM hash leak via crafted .library-ms file in RAR/ZIP archives, triggering SMB authentication on…

Python exploit for CVE-2018-9995 that retrieves exposed DVR credentials by bypassing authentication on vulnerable web interfaces.

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥