
Mailcow-CVE-2022-31138
Mailcow CVE-2022-31138 RCE

Mailcow CVE-2022-31138 RCE

CVE-2024–27631 Reference

Whisker is a C# tool for taking over Active Directory user and computer accounts by manipulating their msDS-KeyCredentialLink attribute, effectively…

Reconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which…

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

CVE-2019-12836

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

CVE-2025-33073

An authenticated Stored Cross-site Scripting (XSS) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file…

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG…

Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbitrary code via crafted SVG…

A Powerful Subdomain Takeover Tool

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Drop a single binary into a compromised Kubernetes pod and instantly map every realistic attack path to cluster-admin, node escape, secret theft,…

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Takeover Account OpenSSH