bigb0x

Elite
@bigb0x

CVE-2024-36991. POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.

127

CVE-2024-7928. Will attempt to retrieve DB details for FastAdmin instances

68

CVE-2024-6387. Bulk Scanning Tool for OpenSSH CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others.

35

CVE-2024-36401. POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.

34

CVE-2024-40348. POC for CVE-2024-40348. Will attempt to read /etc/passwd from target

31

CVE-2024-34102. POC for CVE-2024-34102. A pre-authentication XML entity injection issue in Magento / Adobe Commerce.

31

ssh-log-auditor. Python

28

OpenSSH-Scanner. OpenSSH Vulnerabilities Scanner: Bulk Scanning Tool for 21 different OpenSSH CVEs.

16

CVE-2024-28995. CVE-2024-28995 POC Vulnerability Scanner

14

CVE-2024-29973. POC for CVE-2024-29973

10

CVE-2024-31982. POC for CVE-2024-31982: XWiki Platform Remote Code Execution > 14.10.20

10

CVE-2024-4879. Bulk scanning tool for ServiceNow CVE-2024-4879 vulnerability

10

CVE-2024-7954. This exploit will attempt to execute system commands on SPIP targets.

6

CVE-2024-34470. POC and bulk scanner for CVE-2024-34470

5

CVE-2024-21514. SQL Injection POC for CVE-2024-21514: Divido payment extension for OpenCart

4

CVE-2024-24919-Sniper. CVE-2024-24919 Sniper - A powerful tool for scanning Check Point Security Gateway CVE-2024-24919 vulnerability. Supports single & bulk scanning, multithreading, and generates detailed CSV reports. Ideal for penetration testers and security researchers.

3

CVEs. My publicly published CVEs

2

JEA-Tool. A PowerShell script to configure Just Enough Administration (JEA) for automation tools like Ansible and BMC Discovery.

1

shodan-parser. Python

1

CVE-2024-21887. This is a modified version of "CVE-2024-21887 Exploit Tool " A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

1

CVE-2024-36527. POC for CVE-2024-36527: puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal

1
21
Apply