
subzy
Subdomain takeover vulnerability checker

Subdomain takeover vulnerability checker

CVE-2026-21858

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…


CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

This vulnerability could allow a malicious user to execute remote code by sending appropriately crafted requests to the default search engine…

Technical Reference to multiple relay techniques

Proof of concept script to check if the site is vulnerable to CVE-2023-35078


eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

CVE-2020-35847, CVE-2020-35848 : Account Takeover

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

CVE-2026-8181 — Burst Statistics WordPress plugin Authentication Bypass (CVSS 9.8) to Admin Account Takeover. Mass scanner with FOFA/Shodan…

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…