
CVE-2021-22911
Python exploit script for CVE-2021-22911 targeting Rocket.Chat admin password reset via unauthenticated user registration. Automates exploitation…

Python exploit script for CVE-2021-22911 targeting Rocket.Chat admin password reset via unauthenticated user registration. Automates exploitation…

An unauthenticated PoC for CVE-2020-0796

Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

Hunt down social media accounts by username across social networks

Find specific users in active directory via their username and logon IP address

Different methods to get current username without using whoami

Unauthenticated Xerte Online Toolkits exploit. Requires knowing a valid username.

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

Grafana Bruteforce tool

A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…