
CVE-2023-28810
Unauthenticated configuration changer, password brute-forcer, and SIP ghost caller for Hikvision intercom devices exploiting CVE-2023-28810.

Unauthenticated configuration changer, password brute-forcer, and SIP ghost caller for Hikvision intercom devices exploiting CVE-2023-28810.

Python script that brute-forces Ghost CMS credentials, then checks for CVE-2024-23724 and generates an SVG exploit payload for confirmed vulnerable…

Proof-of-concept exploit for CVE-2024-23724 in Ghost CMS, demonstrating privilege escalation via malicious SVG profile image upload.

Python exploit for CVE-2023-40028 in Ghost CMS, enabling arbitrary file read via symlink abuse in ZIP uploads. Includes automated cleanup.

Proof-of-concept exploit for CVE-2023-40028, demonstrating arbitrary file read in Ghost CMS via improper file handling. For educational and…

Chef cookbook to automate glibc update and remediate CVE-2015-0235 (GHOST) vulnerability on Ubuntu and CentOS with reboot handling.

Exploit PoC for CVE-2026-24061, a critical remote authentication bypass in GNU Inetutils telnetd, giving an unauthenticated root shell via USER=-f…

Buffer overflow exploit for glibc's gethostbyname*() (CVE-2015-0235) with CFEngine policy integration for vulnerability detection and inventory…

Script to test vulnarability for CVE-2015-0235

Pyrescom Termod proof-of-concept code for CVE-2020-23160, CVE-2020-23161 and CVE-2020-23162