
secretsdump.py
Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

Masteriyo LMS <= 2.1.6 - Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator

User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration

Unauthenticated Privilege | Unauthenticated Arbitrary File Upload

Detection of the React Server Actions Exploit vector – CVE-2025-55182 / CVE-2025-66478

Docker-based lab reproducing CVE-2023-26482 (Nextcloud RCE) with automated exploit script for educational vulnerability analysis and exploitation…

C# tool for automated password spraying attacks against Active Directory users via LDAP, with configurable delays and password lists, designed for…

Fortinet announced two closely related authentication‑bypass vulnerabilities on 9 December 2025. Both flaws involve improper verification of…

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

Chromebackdoor is a PoC of pentest tool, this tool use a MITB technique for generate a windows executable ".exe" after launch run a malicious…


A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.

it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script…

Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

Simple shell script to automatically request new Tor identity at configurable intervals for IP rotation.

Python exploit script for CVE-2024-1709, an authentication bypass vulnerability in ConnectWise ScreenConnect. Adds a new administrative user to the…

Multithredded DoS Python Script For CVE-2023-30800