
wp2shell
CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

Moodle 4.5.0-4.5.2 Unauthenticated REST API User Data Exposure via Stack Trace Args Leak | CVSS 7.5


CVE-2021-43798 MiNi Exploitation Framework

Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)


HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc


Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

A technical case study and exploitation analysis of the Authentication Bypass vulnerability in TP-Link TL-WR840N firmware (CVE-2018-12633).

DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

Python script to execute CVE-2025-24071

Laravel Crypto Killer Mass Scanner (CVE-2024-55555)

CVE-2022-0169 - WordPress Photo Gallery SQLi PoC

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.