
CVE-2025-21574-Exploit
Black-box exploit for CVE-2025-21574 targeting MySQL servers. Automates credential brute-forcing, anonymous access attempts, and triggers server…

Black-box exploit for CVE-2025-21574 targeting MySQL servers. Automates credential brute-forcing, anonymous access attempts, and triggers server…


CVE-2025-2539 - WordPress File Away <= 3.9.9.0.1 - Arbitrary File Read

CVE-2020-35847, CVE-2020-35848 : Account Takeover

Exploit for CVE-2018-9995 to retrieve DVR credentials via directory traversal, with two methods for educational use.

Proof-of-concept exploit for user enumeration vulnerability in Supravizio BPM 10.1.2 via password recovery response differences, enabling brute force…

Better version of rastating.github.io/bludit-brute-force-mitigation-bypass/

Step-by-step walkthrough of exploiting CVE-2024-21413 in Microsoft Outlook to bypass Protected View and leak NTLM credentials via Moniker Links,…

exploit of CVE-2022-0847 which directly remove password of the root account

This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).

Scripts to test and exploit the Zerologon vulnerability (CVE-2020-1472) in Active Directory, enabling password reset and hash dumping of domain…

Скрипт для расшифровки пароля пользователя в СЭД Detrix

Bludit 3.9.2 - Remote command execution - CVE-2019-16113

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

Shell script collection for SMB protocol auditing, vulnerability detection (EternalBlue, SMBGhost), null session enumeration, credential brute-force,…

CVE-2008-5161 OpenSSH 4.7p1 Audit Helper Automates version checking and credential auditing of legacy OpenSSH 4.7p1 (Debian-8ubuntu1) targets by…

iOS Shortcut-based keylogger designed to capture keystrokes and exfiltrate data from compromised devices.