
springhound
Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…
Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

Bypassing NTFS permissions to read any files as unprivileged user.

Exploits CVE-2021-40444 in Microsoft Office Word to achieve remote code execution through the MSHTML engine by injecting malicious content into a…

Proof-of-concept exploit for CVE-2017-8295, a WordPress password reset vulnerability allowing attackers to obtain reset links without authentication,…

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

Proof-of-concept exploit for CVE-2023-37250, a local privilege escalation vulnerability in Windows, with a detailed write-up explaining the roaming…

Exploit updated to use Python 3.

Python script to exploit CVE-2023-38646 Metabase Pre-Auth RCE via SQL injection

Exploit for CVE-2021-44667 targeting Alibaba Nacos 2.0.3, enabling unauthenticated remote code execution via a crafted request to the Derby database…

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…

Python script get image from Hikvision camera with CVE-2017-7921 vulnerability

Exploit for CVE-2023-38646 in Metabase, achieving remote code execution and privilege escalation to root via unshare and setuid techniques.

Vulnerable app with examples showing how to not use secrets

double-free bug in WhatsApp exploit poc

Detailed technical analysis and proof-of-concept exploit for CVE-2024-30051, a heap-based buffer overflow in the Windows DWM Core Library enabling…

Double-Free BUG in WhatsApp exploit poc.

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…