
CVE-2017-7921
HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

Username Enumeration in Trivision NC-227WF

Proof-of-concept for CVE-2025-24071, demonstrating NTLM hash leak via crafted .library-ms file in RAR/ZIP archives, triggering SMB authentication on…


CVE-2025-2539 - WordPress File Away <= 3.9.9.0.1 - Arbitrary File Read

Proof-of-concept exploit for user enumeration vulnerability in Supravizio BPM 10.1.2 via password recovery response differences, enabling brute force…

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

Exploit tool for CVE-2018-9995 that extracts credentials from vulnerable DVR devices via Google dorking and direct IP access.

Exploit for CVE-2018-9995 targeting DVR devices. Sends a crafted Cookie header to retrieve plaintext admin credentials from the web control panel.

ThinkAdmin v5 v6 任意文件读取漏洞利用,可自定义字典爆破

Proof-of-concept exploit for CVE-2023-22074, an Oracle Database Sharding component vulnerability enabling password hash exposure in versions 19c,…

Proof-of-concept demonstrating plaintext password storage vulnerability in Digisol DG-GR1321 routers, enabling credential exposure and unauthorized…

Batch exploit script for CVE-2020-25078 targeting D-Link DCS series cameras to extract account credentials via information disclosure vulnerability.

Targets versions ≤2.7.5 vulnerable to CVE-2023-5359

Proof-of-concept for CVE-2023-0860, demonstrating unauthenticated brute-force login attacks on Modoboa Mail Hosting and Management before v2.0.3.

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to > store authentication data

PowerShell-based Active Directory enumeration tool for gathering network configuration, domain objects, user sessions, share permissions, and…

Project with sublist3r, massan, CVE-2018-15473, ssh bruteforce, ftp bruteforce and nikto.