
CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction
Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

A nice tool that automates network hash capturing and has a nice GUI. Read README.md for more information and NEVER use this without explicit…

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on…

This repo shows an exploit to CVE-2021-24762. This is an Blind SQLi exploit that, on default config, greps the admin password.

This is a python PoC scripts for CVE-2025-24071 which is a vulnerability in Windows File Explorer that allows unauthorized access to sensitive…

A ToolKit that automatically installs & configures all the Tools needed to turn your Daily Driver Linux Distro into a Pentesting Machine

Script in Go that analyzes a list of passwords based on in its entropy and weak passwords from a dictionary. Useful for penetration tests and…

Exploit for CVE-2025-44203 targeting a race condition in HotelDruid 3.0.0/3.0.7 that leaks admin credentials and causes denial of service. Includes a…

Kraker is a distributed password brute-force system that focused on easy use.

A password guessing tool that targets the Kerberos and LDAP services within the Windows Active Directory environment.

BruteSploit is a collection of method for automated Generate, Bruteforce and Manipulation wordlist with interactive shell. That can be used during a…

SocialPwned is an OSINT tool that allows to get the emails, from a target, published in social networks such as Instagram, Linkedin and Twitter to…

Generate mutations over a wordlist

Git All the Payloads! A collection of web attack payloads.

Bash script wrapping Active Directory tools for automated enumeration, vulnerability checks, exploitation, and password dumping via LDAP, RPC,…


A WiFi security auditing software mainly based on aircrack-ng tools suite