
CredSniper
CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

Python script to detect CVE-2024-23113, a format string vulnerability in FortiGate FGFM service on TCP/541, using SSL connection and crafted payload…

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…

Proof-of-concept exploit for CVE-2020-8289 demonstrating remote code execution as SYSTEM/root via Backblaze backup client's SSL verification bypass…

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

Proof-of-concept scanner for Apache HTTP Server path traversal (CVE-2021-41773) with multi-host support, SSL verification toggle, and concurrent…

CVE-2026-39987 for marimo 0.20.4 PoC

Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation…

Python script to check for CVE-2024-3400 vulnerability in Palo Alto Networks PAN-OS SSL VPN by probing /ssl-vpn/hipreport.esp and verifying file…

Proof-of-concept exploit for Apple SSL/TLS verification vulnerability (CVE-2014-1266) in iOS and OS X, demonstrating HTTPS interception via a proxy…


Exploit for CVE-2018-13379: unauthenticated path traversal in Fortinet FortiOS SSL VPN portal allowing system file download via crafted HTTP requests.

Proof-of-concept exploit for CVE-2024-24919, an unauthenticated arbitrary file read vulnerability in Check Point SSL VPN appliances. Includes Nuclei…

Python exploit script for CVE-2024-9474 targeting PAN-OS SSL VPN, enabling remote code execution and reverse shell deployment for penetration testing.

Detects and exploits CVE-2024-21762 pre-authentication RCE in FortiGate SSL VPN, featuring baseline validation, automatic exploitation, ROP…

CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC

PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerability

Exploit for CVE-2018-13379 targeting Fortinet SSL VPN path traversal vulnerability. Enables automated exploitation and credential extraction for…