
CVE-2024-55591-POC
A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder

Some Pentest Tools. Install and keep up to date some pentesting tools. I used this to pass my OSCP exam.

Hacking systems with the automation of PasteJacking attacks.

All-in-one exploit tool for CVE-2026-27966, a critical RCE in Langflow. Features mass scanning, auto-detection, payload execution, interactive shell,…

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

dns rebind tool with custom scripts

Proof-of-concept exploit for CVE-2021-24307, an authenticated admin RCE in All in One SEO Pack <= 4.1.0.1 via PHP unserialization, enabling arbitrary…

CVE-2021-4045 CVE-2021-4045 is a Command Injection vulnerability that allows Remote Code Execution in the TP-Link Tapo c200 IP camera. It affects all…

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

ALL In One Custom Login Page <= 7.1.1 - Missing Authorization to Authenticated (Subscriber+)Privilege Escalation

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

Propovoice <= 1.7.6.7 - Unauthenticated Arbitrary File Read

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is…

Do you really think SharePoint is safe?

All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection

New exploitation of 2020 Sophos vuln