
CVE-2021-27651
bypass all stages of the password reset flow

bypass all stages of the password reset flow

wpsqli full SQLi extractor + dumper for CVE-2026-60137

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

📜 Scrape targeted wordlists for password cracking using CSS selectors

Highly configurable script for dictionary/spray attacks against online web applications.

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will…

A tool to dump the login password from the current linux user

Hashcat wrapper to help automate the cracking process

Proof-of-concept for CVE-2025-25749 demonstrating weak password policy in HotelDruid 3.0.7, with automated test scripts and mitigation…

A swiss army knife for pentesting networks

Proof-of-concept exploit for CVE-2017-8295, a WordPress password reset vulnerability allowing attackers to obtain reset links without authentication,…

Exploit the Redash weak secret key vulnerability (GHSA-g8xr-f424-h2rv) to generate password reset links for any user, enabling account takeover…

This is the exploit of CVE-2019-17240.

Exploit for CVE-2024-56429 demonstrating extraction of Apache Derby database boot password from iLabClient source code, enabling local database…

Lookup for interesting stuff in SMB shares