
SpotifyC2
Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…


GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…


Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

CVE-2017-7679 POC SCRIPT BY LORDWARE....

A standalone Blind XSS Script.

Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

PoC Exploit for CVE-2025-7753 — Time-Based SQL Injection in Online Appointment Booking System 1.0 via the username parameter. Exploit written in C…

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass


OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

Exploitation Framework for ATtiny85 Based HID Attacks