
0day-Rubbish
Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to…

Redefining vulnerability disclosure in the AI era. We mass-produce exploitable 0days and disclose them directly, using event-driven pressure to…

Small script to retrieve passwords from many types of Moxa device, including NPort, OnCell, MGate, etc.

A tool to manipulate Schneider Electric PLC archive files

ISAF aims to be a framework that provides the necessary tools for the correct security audit of industrial (OT) environments.

Detection-engineering reference mapping Windows, cloud, container, identity, and ICS attack classes to Sigma rules, trust-boundary models, BYOVD…

This repository includes the code and files needed to test and execute a PoC for CVE-2025-41656

PoC exploit for CVE-2025-69985: authentication bypass leading to RCE in FUXA SCADA ≤1.2.8. Includes a modular Python exploit with interactive shell,…

TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators


Proof-of-concept exploit for CVE-2021-26828 enabling authenticated remote code execution on ScadaBR SCADA systems via JSP file upload. Supports…

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

PoC for CVE-2018-12086 affecting various OPC UA stacks

Proof-of-concept SQL injection exploit for FUXA SCADA software (<=1.1.12) via HTTP POST JSON id parameter, enabling extraction of SQLite database…

OpenPLC 3 WebServer Authenticated Remote Code Execution.

OpenPLC 3 WebServer Authenticated Remote Code Execution.

Paracosme is a zero-click remote memory corruption exploit that compromises ICONICS Genesis64 which was demonstrated successfully on stage during the…

A Curated list of Security Resources for all connected things
