
Nettacker
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Alibab-Nacos-Unauthorized-Reset PWD

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

Exploit for CVE-2024-48322 targeting RunCodes instances. Retrieves user passwords via email inbox after authentication bypass, requiring only any…

Proof-of-concept exploit for CVE-2017-8295, demonstrating unauthorized password reset in WordPress 4.7.4 by intercepting the reset link without prior…

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0

Exploit tool for CVE-2023-2437 targeting UserPro <= 5.1.1 authentication bypass, allowing attackers to gain admin access and create new…

Exploit for CVE-2025-47227 - ScriptCase Password Reset (Pre-Auth)

WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

Open-source tool to bypass windows and linux passwords from bootable usb

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

POC tool for ResetNightmare (CVE-2026-27912)

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Writeup of CVE-2020-15906