
nrf24-injection
A tool set for sniffing devices and launching attacks with Crazyradio

A tool set for sniffing devices and launching attacks with Crazyradio

Code set relating to CVE-2022-41040

Python script to create a message with the vulenrability properties set

Pivotal CRM's patch for an initial deserialization vulnerability was incomplete. The fix switched from BinaryFormatter to JSON.NET but left…

We've set up an environment to test CVE-2025-57833. This environment was built using AI, so it's subject to ongoing modification.

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some…


Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).

Docker-compose to set up a test environment for exploiting CVE-2015-8562

A collection of scripts to help set the appropriate registry keys for CVE-2021-34527

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session

Recover the default privilege set of a LOCAL/NETWORK SERVICE account

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

A tool for checking if MFA is enabled on multiple Microsoft Services

Extract credentials from lsass remotely