
Linux-Kodachi
Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

Hardened Debian-based privacy OS with pre-integrated anonymity stack (Tor, VPN, DNSCrypt), anti-forensic tooling, SOC security center, and standalone…

Automated OSINT reconnaissance tool that queries Google and social platforms to gather intelligence on usernames and queries, with proxy rotation and…

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

Security Advisory: Unauthenticated Stored Cross-Site Scripting Leading To Administrator Account Takeover (openclaw-dashboard)

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

OsintNET is a browser-based OSINT platform for domain intelligence, website risk scanning, SERP discovery, image intelligence and AI image detection.

Proof-of-concept for SQL injection in CodeAstro Simple Attendance Management System 1.0, demonstrating authentication bypass via crafted username…

Demonstrates user enumeration in FormaLMS via response discrepancy on the /lostpwd endpoint, enabling unauthenticated username discovery for targeted…

OSINT Graph Investigation Application

Browser extension for OSINT research enabling username, email, and phone number searches across 20+ platforms with integrated access to GHunt,…

Stored XSS proof-of-concept for SOGo groupware, exploiting the 'Remember Username' cookie to inject JavaScript payloads via the login endpoint.

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

PoC for Silverpeas <= 6.4.2 Username Enumeration

POC For CVE-2020-1481 - Jira Username Enumerator/Validator

Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI

Proof-of-concept Python script that enumerates valid ServiceNow user accounts by exploiting the password-reset response discrepancy in CVE-2021-45901.

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

Proof-of-concept for a stored Cross-Site Scripting (XSS) vulnerability in Sourcecodester Best Courier Management System v1.0 via the change username…