
TeamPass
Self-hosted collaborative password manager with AES-256 encryption, LDAP/AD integration, role-based access control, REST API, and Docker deployment…

Self-hosted collaborative password manager with AES-256 encryption, LDAP/AD integration, role-based access control, REST API, and Docker deployment…

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

A free, secure and open source app for Android to manage your 2-step verification tokens.

There is a SQL injection vulnerability in the backend of Ruoyi v4.8.3

Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.

Privacy-first password manager with local storage and bring-your-own-cloud sync across Google Drive, Microsoft OneDrive, and Dropbox. Your…

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

Automated exploitation framework for Grafana directory traversal (CVE-2021-43798) with multi-plugin brute-force, batch scanning, credential…

Proof-of-concept exploit for a time-based blind SQL injection in the Relevanssi WordPress plugin, featuring comma-less payloads and CASE WHEN logic…

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

HackTheBox Facts machine writeup — CVE-2025-2304, MinIO S3 enumeration, SSH key cracking, and facter privilege escalation.

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

📜 Scrape targeted wordlists for password cracking using CSS selectors

Time-based blind SQL injection toolkit for CVE-2025-4396 with standard and binary-search extraction scripts, plus automated WordPress 6.8+ hash…

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

Server-side encrypted, self-destructing link service for secure sharing of passwords, documents, and messages. Includes API, password generator, and…

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original…

A cli for cracking, testing vulnerabilities on Json Web Token(JWT)