
CVE-2026-13249
Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit…

Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit…

Takeover Account OpenSSH

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

CVE-2025-58434 and CVE-2025-59528 chain POC

CVE-2025-58434 Flowise <= 3.0.5 and earlier allows account takeover via unauthenticated forgot-password token. CVE-2025-59528 lowiseAI Custom MCP…

Exploit for CVE-2021-22911: pre-auth blind NoSQL injection in Rocket Chat 3.12.1 enabling account takeover and remote code execution via webhook…

Proof-of-concept exploit for CVE-2023-26866: remote command injection in GreenPacket WR-1200 and OT-235 routers enabling pre-login root-level device…

Python proof-of-concept scripts for the MikroTrick MikroTik RouterOS SSH takeover chain (CVE-2026-67279, CVE-2026-86060, CVE-2026-67276) for…