
CVE-2023-30092
Proof-of-concept exploit for SQL injection in Sourcecodester Online Pizza Ordering System 1.0. Demonstrates remote code execution and denial of…

Proof-of-concept exploit for SQL injection in Sourcecodester Online Pizza Ordering System 1.0. Demonstrates remote code execution and denial of…

Exploit for Apache NiFi CVE-2023-34468, targeting a vulnerability in versions 1.21.0 and earlier to demonstrate data access and system compromise.

Local privilege escalation exploit for Windows CVE-2020-17103 in cldflt.sys, abusing a race condition in Cloud Files placeholder handling to elevate…

Proof-of-concept for CVE-2023-46450: authenticated stored cross-site scripting (XSS) vulnerability in the Add Supplier function of Sourcecodester…

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.

Multi-threaded ICMP timestamp scanner that detects hosts vulnerable to CVE-1999-0524 by sending Type 13 requests and analyzing Type 14 replies,…

Proof-of-concept exploit for CVE-2023-46449: IDOR in Sourcecodester inventory management system v1.0 password change function enabling remote account…

Analysis and documentation for CVE-2023-34965, an SSPanel UIM information disclosure that leaks user subscription data via an unprotected /link/…

Reflected Cross-Site Scripting in Snipe-IT CSV Import Workflow

Bash tool that routes all system network traffic through Tor for IP anonymization, with manual/automatic IP rotation and current IP/location display.

A utility for extracting system and application metrics from unprotected Prometheus Node Exporter HTTP endpoints, used to identify misconfigurations…

A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".

A fast multi threaded scanner for Citrix ADC (NetScaler) CVE-2019-19781 - Citrixmash

↕️🤫 Stealth redirector for your red team operation security

Multi-threaded Tor proxy with automatic IP rotation on configurable triggers (string, regex, status code, timeout) for penetration testing, WAF…

Authorized cloud adversary simulation and validation toolkit

Non-intrusive HTTP vulnerability scanner for CVE-2025-49132 that detects exposed database credentials, application keys, and configuration files via…