
cve-2019-17240
Go-based brute-force tool exploiting Bludit bruteforce mitigation bypass (CVE-2019-17240) for automated password cracking against admin login pages.

Go-based brute-force tool exploiting Bludit bruteforce mitigation bypass (CVE-2019-17240) for automated password cracking against admin login pages.

Demonstrates a brute-force attack bypassing two-factor authentication in Nagios Fusion due to missing rate limiting and lockout, with CVE-2025-60424…

CVE-2025-59390 and ThreadLocalRandom Inverse

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

A python3 multithreaded SSH dictionary attack tool

Automated exploit for Rocket.Chat NoSQL injection (CVE-2021-22911) that leaks password reset tokens and performs unauthenticated account takeover.

Unauthenticated Privilege Escalation to Administrator via Role Form Field

python 2.7

Python POC for CVE-2025-5095

Prepostseo Login Checker

PoC for CVE-2021-45041

PoC for CVE-2024-42049

Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

Black-box exploit for CVE-2025-21574 targeting MySQL servers. Automates credential brute-forcing, anonymous access attempts, and triggers server…

Better version of rastating.github.io/bludit-brute-force-mitigation-bypass/

专为红队行动设计的CSRF登录暴力破解工具,具备动态CSRF Token刷新、多线程并发和会话恢复功能,支持高并发操作和智能重试机制。

CVE-2023-30765 / ZDI-23-905 - Delta Electronics Infrasuite Device Master Privilege Escalation