
CVE-2026-26980
Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…


The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

Hunt for and Exploit the libSSH Authentication Bypass (CVE-2018-10933)

PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.

Amplify network visibility from multiple POV of other hosts

smbcrawler is no-nonsense tool that takes credentials and a list of hosts and 'crawls' (or 'spiders') through those shares

Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5)

Scan your IP network and determine hosts with possible CVE-2021-44228 vulnerability in log4j library.


Security Research from the Microsoft Security Response Center (MSRC)

Metasploit custom modules, plugins, resource script and.. awesome metasploit collection

Zabbix vulnerability assessment plugin

Filters host lists to identify viable SSRF candidates by probing HTTP reachability and resolving internal/external IPs, bypassing traditional…


PrintNightmare (CVE-2021-34527) PoC Exploit

