


Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…


Automated Exploit Tool for Grafana CVE-2021-43798: Scanning common files that contain juicy informations and extracting SSH keys from compromised…

https://github.com/milo2012/CVE-2018-0296.git

Automated 8-phase exploit for CVE-2026-8732, an unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0. Uses multiprocessing and asyncio to scan…

Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…

Tool to extract all themes and plugins that are shown on the front page of a wordpress site.

Multi-threaded web crawler for structured site mapping and regex-based data extraction. Exports results in JSON, XML, or TXT for reconnaissance and…

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Uscrapper Vanta: Dive deeper into the web with this powerful open-source tool. Extract valuable insights with ease and efficiency, from both surface…


Informe técnico de una vulnerabilidad ya corregida en Instagram Notes que exponía el audio original de vídeos mediante URLs directas.