
CVE-2026-26980
Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Lightweight RAT providing silent remote command-line access, hidden file download/execution, and persistence mechanisms for Windows systems.…

OTP BOT Bypass SMS verifications from Paypal, Instagram, Snapchat, Google, 3D Secure, and many others...

Chef cookbook to test systems for the GHOST vulnerability (CVE-2015-0235) by running a detection binary and checking libc for the flaw.

Arbitrary file read in Ghost-CMS allows an attacker to upload a malicious ZIP file with a symlink.

Python-based proof-of-concept exploit for CVE-2023-40028, a symlink upload vulnerability in Ghost CMS enabling authenticated arbitrary file read via…

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

Blind SQL injection exploit for Ghost CMS (CVE-2026-26980) targeting unauthenticated Content API to extract credentials, API keys, and database…

Unauthenticated SQL injection proof-of-concept for Ghost CMS Content API (CVE-2026-26980) with Docker lab and boolean-based database extraction.

Proof-of-concept exploit for a stored XSS vulnerability in Ghost CMS (CVE-2025-66849) enabling privilege escalation from Contributor to Owner via…

Pyrescom Termod proof-of-concept code for CVE-2020-23160, CVE-2020-23161 and CVE-2020-23162

Active Directory relay attack detection and enumeration tool. Scans for NTLM relay opportunities, detects CVE-2025-33073, CVE-2025-54918,…

Proof-of-concept exploit for CVE-2023-40028, demonstrating arbitrary file read in Ghost CMS via improper file handling. For educational and…

Proof-of-concept script demonstrating CVE-2023-40028 Local File Inclusion in Ghost CMS via symlink file upload, enabling authenticated attackers to…

Python exploit for CVE-2023-40028 in Ghost CMS, enabling arbitrary file read via symlink abuse in ZIP uploads. Includes automated cleanup.

Unauthenticated configuration changer, password brute-forcer, and SIP ghost caller for Hikvision intercom devices exploiting CVE-2023-28810.

A shared library wrapper with additional checks for vulnerable functions gethostbyname2_r gethostbyname_r (GHOST vulnerability)

Proof-of-concept exploit for CVE-2015-0235 (Ghost), a critical glibc gethostbyname buffer overflow vulnerability enabling remote code execution.