
vbulletin-exploits
Exploits targeting vBulletin.

Exploits targeting vBulletin.

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…


PoC for CVE-2025-8110: Authenticated RCE in Gogs via symlink bypass in PutContents API

load-scripts.php file, which purpose is to retrieve several JavaScript packages through one single request.

Authenticated remote code execution exploit for Windows Admin Center via WinREST/PowerShell invokeCommand; takes credentials and runs arbitrary…

The detection of internal security controls at a company

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminating the need…

Azure AD Password Checker


Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

.NET/PowerShell/VBA Offensive Security Obfuscator

POC for CVE-2022-47966 affecting multiple ManageEngine products

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.