
CVE-2025-14340
PoC for CVE-2025-14340: Admin account takeover in Payara Server

PoC for CVE-2025-14340: Admin account takeover in Payara Server

Takeover of Oracle WebLogic Server

A CSRF POC for Updating the Profile of a Hospital leading to Account Takeover

🦚 A web-app pentesting suite written in rust .



Mailcow CVE-2022-31138 RCE

CVE-2024–27631 Reference

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Orbis is an full spectrum automated external attack surface intelligent toolkit.

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively…

Python 3.5+ DNS asynchronous brute force utility

SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.

Reconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which…

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Automated reconnaissance and vulnerability detection tool that enumerates subdomains, collects URLs, and runs Nuclei scans to identify…

Tool to discover Resource-Based Constrained Delegation attack paths in Active Directory environments