Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.
☆19Feb 4, 2026Updated 6 months ago
Alternatives and similar repositories for CVE-2025-2304
Users that are interested in CVE-2025-2304 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This Python PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0). It allows authenticated use…☆27May 10, 2026Updated 3 months ago
- Repository of various scripts related to Mobile PT. Copyrights and Licensing terms belong to respective owners.☆11Nov 4, 2019Updated 6 years ago
- CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to uploa…☆13Jan 7, 2025Updated last year
- CVE-2023-46818 Python3 Exploit for ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability☆15Apr 16, 2025Updated last year
- PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability☆25Jul 5, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Labs built in docker to cover NSE lessons☆12Nov 24, 2023Updated 2 years ago
- CVE-2025-4138 / CVE-2025-4517 — Python tarfile PATH_MAX Symlink Filter Bypass☆17Jun 4, 2026Updated 2 months ago
- Find secrets and passwords in container images and file systems☆15Nov 16, 2022Updated 3 years ago
- SANS Holiday Hack Challenge write-up template☆28Nov 20, 2023Updated 2 years ago
- File upload logic flaw in Apache Struts2 exploit☆17Jan 3, 2025Updated last year
- Libro de ejercicios de introducción a las redes neuronales☆19Jul 13, 2026Updated 3 weeks ago
- ☆13Jul 24, 2023Updated 3 years ago
- HTTP Headers Security Cheat Sheet☆12Sep 25, 2021Updated 4 years ago
- Proof of Concept for CVE-2025-24367☆37Dec 8, 2025Updated 8 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A searchable, copy-pasteable library of pentesting commands focused on Active Directory. Runs entirely in your browser.☆26Apr 21, 2026Updated 3 months ago
- This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerabi…☆27Apr 27, 2025Updated last year
- Cyber deception with generative cloud-native traps☆15Apr 13, 2025Updated last year
- Unveiling Cyber Threats: From assets to Vulnerability Insights☆18Oct 22, 2024Updated last year
- Cfd (Cloudflare detector) is a tool that allows you to check one or more domains to see if they are protected by CloudFlare or not. The c…☆17Mar 30, 2023Updated 3 years ago
- Script for generating write-ups templates for CTF challenges 🗃️☆15Feb 5, 2022Updated 4 years ago
- Proof of Concept demonstrating Remote Code Execution through insecure deserialization in Roundcube (CVE-2025-49113).☆92Jun 6, 2025Updated last year
- Scripted Local Linux Enumeration & Privilege Escalation Checks☆12Aug 30, 2022Updated 3 years ago
- The Microsoft Student Security Operations Center (SOC) Toolkit is designed to equip facilitators with everything needed to prepare high s…☆25Jul 1, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Groovy Post Exploitation☆19Oct 21, 2024Updated last year
- List of all Red Teaming tools and Techniques for each stages☆22Dec 28, 2022Updated 3 years ago
- Source code for GUIFuzz++: a prototype grey-box fuzzer for GUI-based applications on Linux.☆24Nov 27, 2025Updated 8 months ago
- Monokai Pro color scheme for iTerm2☆15Aug 17, 2024Updated last year
- An interactive, TLS-capable HTTP intercepting proxy designed for penetration testers and software developers, including a parser for the …☆26Jul 31, 2025Updated last year
- 🔍 erroreyes – Lightweight Subdomain Enumeration Tool A Python-based tool that queries crt.sh certificate logs to discover subdomains ass…☆17May 8, 2025Updated last year
- Just a vault template to help someone on the certificate.☆19Sep 3, 2025Updated 11 months ago
- Generate reverse shells in command line with Go !☆20Aug 9, 2020Updated 6 years ago
- Markdown version of OWASP Testing Checklist v4☆14Aug 15, 2017Updated 8 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.☆33Feb 24, 2023Updated 3 years ago
- Transforming Smooth AD Automation Scripts into Attack Vectors☆20Nov 22, 2025Updated 8 months ago
- Testing POC for use cases☆26Nov 24, 2024Updated last year
- A Python script that parses your SUID/SGID enumeration output and checks which binaries are exploitable according to GTFOBins. Supports b…☆35Dec 24, 2025Updated 7 months ago
- Notepad++ Linux Fork☆17Feb 15, 2026Updated 5 months ago
- Registry of shareable ClawFlows automations for OpenClaw agents☆35Apr 25, 2026Updated 3 months ago
- Scripts from Ghidra Golf competitions☆34Jan 24, 2023Updated 3 years ago