
CVE-2019-19633
lib/G/functions.php in Chevereto 1.0.0 through 1.1.4 Free, and through 3.13.5 Core, allows an attacker to perform bruteforce attacks without…

lib/G/functions.php in Chevereto 1.0.0 through 1.1.4 Free, and through 3.13.5 Core, allows an attacker to perform bruteforce attacks without…

Cross-platform credential recovery tool that extracts stored passwords from browsers, email clients, databases, system mechanisms, and network…

Penetration testing tool for Oracle Databases that discovers valid SIDs, brute-forces credentials, escalates privileges to DBA, executes system…

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

Toolset for extracting credentials from Microsoft ConfigMgr/SCCM Operating System Deployment via PXE boot attacks, including password cracking,…

Distributed brute-force password cracking system that parallelizes dictionary and crunch-based attacks across multiple machines via web and desktop…

Active Directory NTDS database parser that dumps records to JSON, supports object filtering, and decrypts encrypted columns using SYSTEM hive or…

Multithreaded Windows secret-dumping utility that pulls NTDS.dit, SAM, and SYSTEM hives from many hosts using Impacket-based remote access.

Advanced hash cracking and manipulation system supporting bruteforce attacks, dictionary generation, automatic hash algorithm verification, and…

Decrypt RunAs credentials from Microsoft System Center Operations Manager (SCOM) servers for post-exploitation and red team operations.

Proof-of-concept exploit for CVE-2023-43261 targeting Milesight industrial routers. Demonstrates credential leakage via unprotected system logs and…

This is a keylogger that collects all the data and e-mail it in a set time with system information which includes device S/N and hardware specs,…

PowerShell-based remote administration tool (RAT) with keylogging, remote shell, and file management capabilities for covert system control.

Modular cybersecurity toolkit for OSINT, forensics, network scanning, and penetration testing with an automation engine, plugin system, and modules…

User Enumeration vulnerability in Kaiten (workflow management system)

Unauthenticated SQL injection exploit for Simple Task Managing System 1.0, targeting login and password parameters to dump database contents via…

Demonstrates a complete WordPress attack chain exploiting CVE-2021-29447 (XXE) to achieve remote code execution, database compromise, and full system…

Python-based exploit for CVE-2022-31890 in osTicket support ticketing system, enabling credential dumping via nickname and password enumeration…