Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.
☆19Feb 4, 2026Updated 7 months ago
Alternatives and similar repositories for CVE-2025-2304
Users that are interested in CVE-2025-2304 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated use…☆28May 10, 2026Updated 4 months ago
- Repository of various scripts related to Mobile PT. Copyrights and Licensing terms belong to respective owners.☆11Nov 4, 2019Updated 6 years ago
- CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to uploa…☆13Jan 7, 2025Updated last year
- CVE-2023-46818 Python3 Exploit for ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability☆15Apr 16, 2025Updated last year
- PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability☆25Jul 5, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Labs built in docker to cover NSE lessons☆12Nov 24, 2023Updated 2 years ago
- CVE-2025-4138 / CVE-2025-4517 — Python tarfile PATH_MAX Symlink Filter Bypass☆17Jun 4, 2026Updated 3 months ago
- SANS Holiday Hack Challenge write-up template☆28Nov 20, 2023Updated 2 years ago
- This repository contains the LaTeX source code for a professional resume tailored for AI/ML roles. The resume is designed to highlight sk…☆21Jun 16, 2024Updated 2 years ago
- File upload logic flaw in Apache Struts2 exploit☆17Jan 3, 2025Updated last year
- Libro de ejercicios de introducción a las redes neuronales☆19Jul 13, 2026Updated 2 months ago
- ☆13Jul 24, 2023Updated 3 years ago
- ☆22Mar 6, 2026Updated 6 months ago
- Proof of Concept for CVE-2025-24367☆38Dec 8, 2025Updated 9 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A searchable, copy-pasteable library of pentesting commands focused on Active Directory. Runs entirely in your browser.☆27Apr 21, 2026Updated 4 months ago
- This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerabi…☆26Apr 27, 2025Updated last year
- Cyber deception with generative cloud-native traps☆15Apr 13, 2025Updated last year
- My Reverse Shell Cheat Sheet☆14Mar 2, 2022Updated 4 years ago
- ☆22Mar 15, 2024Updated 2 years ago
- Unveiling Cyber Threats: From assets to Vulnerability Insights☆18Aug 11, 2026Updated last month
- This repository contains the setup from Paradigm CTF blockchain challenges based on the original repository. We've introduced new featur…☆51Oct 4, 2025Updated 11 months ago
- POC for CVE-2023-38646☆21Dec 7, 2023Updated 2 years ago
- Script for generating write-ups templates for CTF challenges 🗃️☆15Feb 5, 2022Updated 4 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Proof of Concept demonstrating Remote Code Execution through insecure deserialization in Roundcube (CVE-2025-49113).☆92Jun 6, 2025Updated last year
- Proof of Concept for CVE-2025-31161 / CVE-2025-2825☆48Apr 8, 2025Updated last year
- Groovy Post Exploitation☆19Oct 21, 2024Updated last year
- List of all Red Teaming tools and Techniques for each stages☆23Dec 28, 2022Updated 3 years ago
- Source code for GUIFuzz++: a prototype grey-box fuzzer for GUI-based applications on Linux.☆24Nov 27, 2025Updated 9 months ago
- Monokai Pro color scheme for iTerm2☆15Aug 17, 2024Updated 2 years ago
- 🔍 erroreyes – Lightweight Subdomain Enumeration Tool A Python-based tool that queries crt.sh certificate logs to discover subdomains ass…☆17May 8, 2025Updated last year
- An interactive, TLS-capable HTTP intercepting proxy designed for penetration testers and software developers, including a parser for the …☆28Jul 31, 2025Updated last year
- Just a vault template to help someone on the certificate.☆23Sep 3, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Generate reverse shells in command line with Go !☆20Aug 9, 2020Updated 6 years ago
- Additional graphics settings for Lethal Company, such as resolution, anti-aliasing. fog quality etc.☆28Dec 23, 2023Updated 2 years ago
- Markdown version of OWASP Testing Checklist v4☆14Aug 15, 2017Updated 9 years ago
- My backdoor script for a vulnerable version of UnrealIRCd☆26Apr 29, 2024Updated 2 years ago
- Transforming Smooth AD Automation Scripts into Attack Vectors☆20Nov 22, 2025Updated 9 months ago
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆33Feb 24, 2023Updated 3 years ago
- Testing POC for use cases☆26Nov 24, 2024Updated last year