
ZackAttack
Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!

Unveiled at DEF CON 20, NTLM Relaying to ALL THE THINGS!



CVE-2025-0364: BigAnt Server RCE Exploit

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

Exploit script for SAP Business Objects SSRF

Metabase Pre-auth RCE (CVE-2023-38646)

Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases

Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases

WordPress Simple Business Directory Pro Plugin < 15.6.9 is vulnerable to a high priority Privilege Escalation

This is a Proof of Concept (PoC) script for exploiting Metabase, an open-source business intelligence and data analytics tool.

CVE Reproduction: cve-2025-61882-oracle_ebs_rce_reproduction

Security Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management,…

[CVE-2020-6286] SAP NetWeaver AS JAVA (LM Configuration Wizard) Directory Traversal

CVE-2026-46817

Mass CVE-2023-2744

CVE-2024-4443 Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter

Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI