
FinalRecon
Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

Vthunting is a tiny script used to generate report about Virus Total hunting and send it by email, slack or telegram.

Proof-of-concept exploit for a buffer overflow vulnerability in Tenda routers. Sends crafted unauthenticated POST requests to trigger a crash and…

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

Frida-based proof-of-concept demonstrating authentication bypass in Telegram Android by hooking SharedConfig.checkPasscode to always return true,…

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

Research artifact repository containing fuzzing corpora (liblnk, tcpdump, vim), a Telegram privacy vulnerability report, and supporting scripts for…

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

Detailed analysis and PoC for CVE-2025-67887/86 RCE in 1C-Bitrix Translate module, including exploit chain, CVSS scoring, and mitigation…

Exploit Win10Pcap Driver to enable some Privilege in our process token ( local Privilege escalation )

Automated vulnerability scanner for CVE-2023-28121 that checks a list of targets concurrently and delivers results via Telegram notifications.

Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).

Proof-of-concept exploit for CVE-2023-3047 SQL injection vulnerability in TMT Lockcell. Demonstrates manual exploitation using cURL and Burp Suite to…

GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

PoC Exploit for CVE-2025-7753 — Time-Based SQL Injection in Online Appointment Booking System 1.0 via the username parameter. Exploit written in C…

CVE-2017-7679 POC SCRIPT BY LORDWARE....