
CVE-2024-6460
Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI

Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI

VirusTotal Wanna Be - Now with 100% more Hipster

OSINT tool to get information from a Github and Gitlab profile and find user's email addresses leaked on commits.

API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak

Automated OSINT reconnaissance tool that queries Google and social platforms to gather intelligence on usernames and queries, with proxy rotation and…

Benign proof-of-concept for CVE-2026-36227, a path traversal vulnerability in Easy Chat Server 3.1 user registration. Demonstrates unauthorized file…

PoC for Silverpeas <= 6.4.2 Username Enumeration

An OSINT tool to search for accounts by username in social networks.

Python exploit for CVE-2007-2447 in Samba, enabling remote command execution via crafted username. Delivers reverse shell to attacker. For authorized…

Proof-of-concept checker for CVE-2025-11833, allowing security researchers to test vulnerable web applications with configurable credentials and loot…

Exploit for CVE-2025-2304

Exploit for CVE-2024-46987

Educational Docker lab demonstrating Telnet NEW-ENVIRON username injection (CVE-2026-24061) with a Python client and vulnerable server for isolated…

Proof-of-concept exploit for CVE-2020-9496 (Apache OFBiz) with nuclei template integration and step-by-step vulnerable environment setup for security…

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.