
CVE-2025-24799
Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…

Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…


A script to extract domain names from Content Security Policy(CSP) headers

Tool to extract all themes and plugins that are shown on the front page of a wordpress site.

Extract URLs, paths, secrets, and other interesting bits from JavaScript

A simple, reliable and reasonably fast network capture analyzer.

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…


Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Automated 8-phase exploit for CVE-2026-8732, an unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0. Uses multiprocessing and asyncio to scan…

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

https://github.com/milo2012/CVE-2018-0296.git

Just a PoC tool to extract password using CVE-2019-1653.

Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)