
CVE-2022-41272
Improper access control in SAP NetWeaver Process Integration

Improper access control in SAP NetWeaver Process Integration

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)

[CVE-2022-39802] File path traversal vulnerability in SAP Manufacturing Execution

CVE-2020-5902 scanner for F5 BIG-IP with Shodan host discovery, LFI file reading, and remote command execution capabilities.

Exploit for CVE-2023-23752 (4.0.0 <= Joomla <= 4.2.7).

Scanner for CVE-2023-36845 with Shodan and Censys integration for automated host discovery and exploitation of Juniper devices.

Proof-of-concept XSS exploit for Zoho ManageEngine ServiceDesk Plus 9.3 via the PurchaseRequest.do serviceRequestId parameter, demonstrating…

Proof-of-concept for CVE-2019-12542: XSS vulnerability in Zoho ManageEngine ServiceDesk Plus 9.3 via SearchN.do userConfigID parameter, with a…

Exploit for Ninja Forms plugin vulnerability allowing unauthenticated download of submission CSVs to disclose email addresses.

Reflected XSS vulnerability proof-of-concept for HotelDruid 3.0.7, demonstrating arbitrary JavaScript execution via the ripristina_backup parameter…

Exploit blind SQL Injection in (Online Learning Management System)

fsociety Hacking Tools Pack – A Penetration Testing Framework

Inject code and spy on wifi users

Fetch all the URLs that the Wayback Machine knows about for a domain

A DNS rebinding attack framework.

Automated NoSQL database enumeration and web application exploitation tool.

Notes about attacking Jenkins servers

weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-20…