
tugtainer-1.30.2-CVE-2026-55494-and-CVE-2026-62308-to-RCE
A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Script fo testing CVE-2000-0649 for Apache and MS IIS servers

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

PhantomJS uses internal module: webpage, to open, close, render, and perform multiple actions on webpages, which suffers from an arbitrary file read…

This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access…

The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…

Security Incident Response Automated Simulations (SIRAS) are internal events that provide a structured opportunity to practice the incident response…

Triton is a dynamic binary analysis library. Build your own program analysis tools, automate your reverse engineering, perform software verification…

Rust-based Windows PE manual loader that maps and executes x86/x64 executables from memory, demonstrating internal loader behavior and PE structure…

CVE-2022-23779 is a security vulnerability in Zoho ManageEngine Desktop Central ,Testing for CVE-2022-23779 using curl

Atlassian Jira XSS attack via Server Side Request Forgery (SSRF).

A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)

DejaVU - Open Source Deception Framework

Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search

CVE-2025-29927 Proof of Concept

Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)

PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes…