
open-sammy
Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

Demonstrates user enumeration in FormaLMS via response discrepancy on the /lostpwd endpoint, enabling unauthenticated username discovery for targeted…

Exploit for CVE-2025-2304

Exploit for CVE-2024-46987

Small PoC to automate exploitation of CVE-2025-63406.

Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)

Python script for SSH username enumeration using timing-based analysis to identify valid accounts on a target server.

Authentication bypass exploit for Joomla CVE-2023-23752 that leaks administrator credentials and MySQL configuration from vulnerable versions…

Time-based blind SQL injection exploit for CMS Made Simple <= 2.2.9 (CVE-2019-9053) that extracts username, email, password hash, and salt, with…

Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI

cve-2024-42327 ZBX-25623

Apache OfBiz vulns