
admin-panel-finder
Python script to discover admin panel URLs of websites, aiding in security reconnaissance and penetration testing.

Python script to discover admin panel URLs of websites, aiding in security reconnaissance and penetration testing.

Multi-threaded Python scanner for CVE-2026-23550, detecting unauthenticated admin takeover in WordPress Modular DS plugin with full wp-admin…

Bash script for WordPress user enumeration and automated admin account creation, exploiting CVE-2026-23550 to bypass authentication and achieve…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.

An all in one admin panel crawler for pentesters.

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

Azure mindmap for penetration tests

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

Proof-of-concept for CVE-2026-37197: Server-Side Request Forgery (SSRF) in NukeViet CMS v4.5.07 admin remote upload, enabling internal network…

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

CVE-2026-8181 — Burst Statistics WordPress plugin Authentication Bypass (CVSS 9.8) to Admin Account Takeover. Mass scanner with FOFA/Shodan…

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

This C# tool sprays for admin access over the entire domain

TeamCity server scanner to detect CVE-2023-42793

Graphical exploit for CVE-2025-3102 in WordPress SureTriggers plugin, enabling unauthenticated admin user creation via API. Includes vulnerable site…

Automated exploit for CVE-2020-6287 targeting SAP NetWeaver AS JAVA authentication bypass. Creates admin users via LM Configuration Wizard.…