
CVE-2026-26744
Demonstrates user enumeration in FormaLMS via response discrepancy on the /lostpwd endpoint, enabling unauthenticated username discovery for targeted…

Demonstrates user enumeration in FormaLMS via response discrepancy on the /lostpwd endpoint, enabling unauthenticated username discovery for targeted…

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Interactive password profiler that generates targeted wordlists by gathering personal details about a user, used for penetration testing and forensic…

A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak

CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability

sprint encode (plan text) get enc password

Remotely test password strength of WordPress bloging software

Code developed to steal certain browser config files (history, preferences, etc)

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.

Username enumeration and password spraying tool aimed at Microsoft O365.

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

This module sniff username and password of unprotected protocols.

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

Time-based blind SQL injection exploit for CMS Made Simple <= 2.2.9 (CVE-2019-9053) that extracts username, email, password hash, and salt, with…

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

VirusTotal Wanna Be - Now with 100% more Hipster

A lightweight CLI tool to interactively search and access your KeePassXC database entries using fzf. Fast, secure, and terminal-centric.

Apache OfBiz vulns