
kaboom
A tool to automate penetration tests

A tool to automate penetration tests

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE

A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:

LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000

wpsqli full SQLi extractor + dumper for CVE-2026-60137

CVE-2025-51482 POC, Dump Credentials From zm.Users

This is a Proof-Of-Concept of CVE-2025-63353

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

CVE-2018-13379 mass exploiter for Fortinet FortiOS SSL VPN. Extracts credentials instantly, saves to CSV + PostgreSQL. Multi-threaded, no bullshit…

Exploit for CVE-2024-46987 path traversal in Camaleon CMS enabling arbitrary file download and automated SSH key extraction via brute-force.

It is the details of CVE-2025-45466

CVE-2025-2539 - WordPress File Away <= 3.9.9.0.1 - Arbitrary File Read

CVE-2020-35847, CVE-2020-35848 : Account Takeover

CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

Educational lab demonstrating detection and mitigation of CVE-2023-32243 privilege escalation in WordPress Essential Addons for Elementor, using…