
gardyn-hack
CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

Exploit for CVE-2025-27580: A predictable token vulnerability in NIH BRICS through 14.0.0-67 allows unauthenticated users with a Common Access Card…

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

Unauthenticated blind SQL injection exploit for Metabase, exploiting a raw SQL injection in the password reset endpoint to extract data via…

CVE-2026-23760 - An authentication bypass via password reset API in SmarterMail.

Exploit for CVE-2026-3844, an unauthenticated arbitrary file upload leading to RCE in Breeze Cache WordPress plugin. Includes lab setup, usage, and…

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

Docker Compose setup to demonstrate the nginx-ui missing authentication vulnerability