
ZeroCrumb
Dumping App Bound Protected Credentials & Cookies Without Privileges.

Dumping App Bound Protected Credentials & Cookies Without Privileges.

Burp Suite extension to perform Kerberos authentication

Burp proxy text log converter to CSV and SQLLite

Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass

PoC for J2Store CVE-2026-67358–67362 (J2Commerce security advisory Aug 2026)

CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)

Lightweight HTTP/2 probes for controlled validation of CVE-2019-9511 (Data Dribble) and CVE-2019-9513 (Priority Churn) DoS vectors in authorized…

Script em python scanner safe-check da CVE-2025-23419

Proof of Concept for CVE-2024-32002: Git submodule path injection vulnerability.

CVE-2024-48955_Overview

Reflected XSS via search GET Parameter in Phoca Download

PoC and detection templates for pre-auth RCE and payment tampering in Balbooa Forms (Joomla), including Python exploit and Nuclei detection template.