
cookie-monster
BOF-based tool to extract browser cookies and credentials from Chrome, Edge, and Firefox via handle duplication and fileless download, with offline…

BOF-based tool to extract browser cookies and credentials from Chrome, Edge, and Firefox via handle duplication and fileless download, with offline…

Authenticated remote code execution exploit for Group-Office via TNEF attachment handler, targeting CVE-2026-25512 with OS command injection.

Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution

WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some…

POC about Web3 – Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass Wordpress plugin

Repository that contains a CVE-2020-11651 Exploit updated to work with the latest versions of python.

Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the Plural Handle…

PHP CGI Argument Injection.

This repository contains a python script that will handle the majority of the dompdf cached font exploit (CVE-2022-28368), all you need to do is…

Dlink 615/815 shell PoC

Simple C# implementation of CVE-2017-8759