
Nosql-MongoDB-injection-username-password-enumeration
Using this script, you can enumerate Usernames and passwords of Nosql(mongodb) injecion vulnerable web applications.

Using this script, you can enumerate Usernames and passwords of Nosql(mongodb) injecion vulnerable web applications.

This repository presents a proof-of-concept of CVE-2023-7028

海康威视未授权访问检测poc及口令爆破

Facebook brute forcer script

Ruijie-RG-EW1200G CVE-2023-4169_CVE-2023-3306_CVE-2023-4415

Framework for penetration testing. The software can identify everything from cross-site scripting to SQL injection. Developers can also use this…

CVE-2019-9053 Exploit for Python 3

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)

The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.

Brute-force tool for WordPress Plugin Limit Login Attempts Reloaded >=2.13.0 - Login Limit Bypass (CVE-2020-35590)

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

POC of CVE-2014-0166 (WordPress cookie forgery vulnerability)

PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon,…

This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made…

A proof of concept for CVE-2022-30600

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection…

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…