
CVE-2023-22621-POC
CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5

CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

Root-Level RCE via OS Command Injection in Ivanti Sentry

CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…

PrestaShop AdminLogin Email Enumeration PoC - CVE-2025-51586. This repository provides an ethical Proof-of-Concept (PoC) for the PrestaShop…

I contacted the monica development team via email on 11/20/2024. I also contacted them via LinkedIn, and other platforms in the weeks that followed.…

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

Code-projects Ticket Booking 1.0 is vulnerable to SQL Injection via the > Email parameter

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).


CVE-2023-5561-PoC

Fileless lateral movement tool that relies on ChangeServiceConfigA to run command

SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order…

An OSINT tool that helps detect members of a company with leaked credentials

A Golang implant that uses Slack as a command and control server

raven is a Linkedin information gathering tool that can be used by pentesters to gather information about an organization employees using Linkedin.

Lightweight Go binary that joins a device to a Tailscale network and exposes a local SOCKS5 proxy for ephemeral red team access. Supports…