
CVE-2025-4396
CVE-2025-4396 - WordPress Relevanssi Time-Based Blind SQL Injection

CVE-2025-4396 - WordPress Relevanssi Time-Based Blind SQL Injection
Project: vsFTPd 2.3.4 backdoor exploitation (CVE-2011-2523) on Metasploitable 2.

This repository contains a practical research and validation toolkit for CVE-2025-4396, an unauthenticated Time-Based Blind SQL Injection affecting…

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

C-Ark Credential Decoder for #CVE-2021-31796

Details about CVE-2018-16987 - Cleartext storage of TA servers' passwords in Squash TM

CVE-2020-27688

CVE-2026-39031 — offline plaintext password recovery for Lansweeper lsrunase 2.0 / lsencrypt 2.0 via a hardcoded RC4 key. PoC + technical advisory.

Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)

Python toolkit for decrypting AES-256 and cracking PBKDF2 passwords from Grafana databases usually paired with (CVE-2021-43798)

Combined PoCs for rConfig: SQL Injection (CVE-2020-10220) & Command Injection (CVE-2020-10879)

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).

Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability

Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔…

Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.

Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE…