
CVE-2023-23397
Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Malicious shortcut generator for collecting NTLM hashes from insecure file shares.


CVE-2023-23397 PoC

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

PoC exploit for CVE-2025-24071, a Windows File Explorer spoofing vulnerability that leaks NTLM hashes via malicious .library-ms files in RAR/ZIP…

CVE-2023-24055 PoC (KeePass 2.5x)

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

Weaponized exploit script for CVE-2020-35575, a password-disclosure vulnerability in TP-Link router web interfaces, granting remote administrative…

Detailed CVE-2026-8697 writeup with POC exploit for a login rate-limit bypass on TP-Link Archer C64 routers via a debug SSH service, enabling…

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

A little tool to play with Kerberos.

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted…

cve-2016-16113

CVE-2023-6875 exploit written for Xakep.Ru

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…

Strapi Framework, 3.0.0-beta.17.4