
PySQLRecon
Offensive MSSQL toolkit written in Python, based off SQLRecon

Offensive MSSQL toolkit written in Python, based off SQLRecon

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

[CVE-2020-14882] Oracle WebLogic Server Authenticated Remote Code Execution (RCE)

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

CVE-2026-20896 Gitea Docker X-WEBAUTH-USER auth bypass checker

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

Full unauthenticated RCE proof of concept for Rocket.Chat 3.12.1 CVE-2021-22911

Unauthenticated Stored XSS in Joomla Helix Ultimate (JoomShaper) <= 2.2.6

CVE-2026-48908

CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full…

CVE-2025-6254 — Doctreat Core <= 1.6.8 — Unauthenticated Privilege Escalation


Proof of concept exploit for CVE-2025-9074 - Unauthenticated Docker Engine API container escape affecting Docker Desktop < 4.44.3 on Windows and…

a lightweight JavaScript snippet showcasing how unauthorized password changes can be triggered on vulnerable Fortinet FortiSwitch GUI endpoints.

CVE-2025-64446


CVE-2026-34197
