View Chocapikk's full-sized avatar
👻
👻

Highlights

  • Pro

Block or report Chocapikk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chocapikk/README.md

Valentin Lobstein

Security Researcher & Exploit Developer @ VulnCheck (@vlobstein-vc)

Just a guy who likes breaking stuff. Can't stop looking for bugs. Sometimes I forget to breathe.

Blog · Twitter · LinkedIn · Ko-fi


84 CVEs · 6 on VulnCheck KEV · Referenced by CERT-FR & BSI


Notable Research

CVETargetImpactRef
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla)Unauth RCE via PHP object injection + XOR keystream recoveryVulnCheck · Blog
CVE-2026-60105Monsta FTPUnauth SSRF via IPv4-mapped IPv6 blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBillingDup SSTI escalated to full RCE via getDi()VulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3CUnauth RCE via pickle deserializationVulnCheck · Blog
CVE-2026-29059Windmill + Nextcloud FlowUnauth RCE chain (5 stages)CERT-FR · BSI · Blog
CVE-2026-39912Xboard / V2Board (7k+ instances)Unauth account takeover via token leakBlog · Exploit
CVE-2026-28515..17openDCIMUnauth RCE (3 chained vulns)VKEV · VKEV · Blog
CVE-2026-27760OpenCATSUnauth RCE via installer code injectionVKEV
CVE-2026-29514NetBoxLow-priv RCE via Jinja2 sandbox bypassBlog · PR
CVE-2025-2611ICTBroadcastUnauth RCE via cookie injectionVKEV · Blog
CVE-2025-34147..52Aitemi M300 WiFi Repeater6 unauth command injectionsCERT-FR · Blog
CVE-2024-22899..03Vinchin Backup & RecoveryExploit chainExploit
All CVEs (84)
CVEDescriptionLinks
CVE-2026-73373Joomla! Core: unrestricted upload of SHTML files leading to code execution (1.0.0-5.4.7, 6.0.0-6.1.2)NVD
CVE-2026-14863FileRun: auth RCE via OS command injection in thumbnail generation (ffmpeg/ImageMagick)Advisory · Blog
CVE-2026-66732 & CVE-2026-66733Sonic 3 A.I.R.: missing source address validation + unbounded memory allocation DoSAdvisory
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla): unauth PHP object injection via XOR keystream recovery, RCE on Joomla 3.9-5.2.1VulnCheck · Blog
CVE-2026-60105Monsta FTP: unauth SSRF via IPv4-mapped IPv6 (::ffff:) blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBilling: SSTI to RCE via getDi() DI container (PDO access) in unsandboxed Twig rendering - VulnCheck KEVVulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3C: unauth RCE via pickle.loads() deserialization in inference APIVulnCheck · Blog
CVE-2026-29514NetBox: low-priv RCE via Jinja2 SandboxedEnvironment bypass in ExportTemplateBlog · PR
CVE-2026-29059Windfall: unauth path traversal + file read in Windmill & Nextcloud Flow - VulnCheck KEV - CERT-FRBlog · Toolkit · CERT-FR
CVE-2026-23696Windmill SQLi in folder management to JWT secret leak to token forge to RCEBlog
CVE-2026-22683Windmill operator role bypass: operators can create/execute scripts despite documentationBlog
CVE-2026-39912Unauth account takeover in Xboard & V2BoardBlog · Exploit
CVE-2026-28515 to CVE-2026-285173 chained vulns in openDCIM: unauth RCE on Docker - 28515 & 28517 on VulnCheck KEVBlog · Exploit
CVE-2026-27760PHP code injection in OpenCATS installer AJAX endpoint - VulnCheck KEVBlog · VulnCheck
CVE-2026-27743 to CVE-2026-277475 vulns in SPIP plugins: 2 SQLi, 2 RCE, 1 XSSBlog
CVE-2026-27174 to CVE-2026-271818 vulns in MajorDoMo: 3 RCE, SQLi, 3 XSSBlog
CVE-2026-25874Unauth RCE via Pickle in HuggingFace LeRobot (21.5k stars)Blog
CVE-2026-25873Unauth RCE via Pickle in OmniGen2 reward serverBlog
CVE-2026-29023Hard-coded API key in Keygraph Shannon routerNVD
CVE-2026-26210Unauth RCE via Pickle in KTransformers (16.5k stars)Blog · Fix PR
CVE-2026-26220Unauth RCE via Pickle in LightLLMBlog
CVE-2026-26215Unauth RCE via Pickle in manga-image-translatorBlog · VulnCheck
CVE-2025-34433Unauth RCE in AVideo via predictable installation saltBlog · VulnCheck
CVE-2025-34434 to CVE-2025-344429 additional vulns in AVideo: IDORs, open redirects, info disclosureBlog
CVE-2025-34452Path Traversal + SSRF in StreamaBlog · VulnCheck
CVE-2025-34147 to CVE-2025-341526 unauth command injections in Aitemi M300 - CERT-FRPart 1 · Part 2 · CERT-FR
CVE-2025-30007 & CVE-2025-30008Unauth XSS in Vembu BDRSuiteBlog
CVE-2025-2611ICTBroadcast unauth RCE - VulnCheck KEVGitHub · VulnCheck KEV
CVE-2025-2609 & CVE-2025-2610Stored XSS in MagnusBillingBlog · VulnCheck
CVE-2025-2292, CVE-2025-30004 to CVE-2025-30006Auth vulns in Xorcom CompletePBXVulnCheck
CVE-2024-31819Unauth RCE in AVideoGitHub
CVE-2024-35373 & CVE-2024-353742 unauth RCE in MocodoBlog
CVE-2024-30920 to CVE-2024-30929, CVE-2024-31818Research in DerbyNetGitHub
CVE-2024-22899 to CVE-2024-22903, CVE-2024-25228Exploit chain in Vinchin Backup & RecoveryGitHub
CVE-2024-3032Themify Builder Open RedirectWPScan
CVE-2023-50917RCE in MajorDoMoGitHub

Tools

ToolDescription
wpprobeFast WordPress plugin enumeration (930+ stars) - in Kali, BlackArch, NixOS, Exegol
cewlaiAI-powered wordlist generator (CeWL + CUPP + LLM in one binary)
pgreadDump PostgreSQL data from heap files without credentials
LFIHuntScan & exploit Local File Inclusion
msf-exploit-collectionAll my Metasploit modules in one place

Hall of Fame

Ferrari (2023) · Siemens (2024) · Philips (2024) · Wikimedia (2024)

Pinned Loading

  1. wpprobewpprobePublic

    A fast WordPress plugin enumeration tool

    Go 942 124

  2. CVE-2026-21858CVE-2026-21858Public

    n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

    Python 259 51

  3. CVE-2023-29357CVE-2023-29357Public

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Python 238 33

  4. CVE-2024-25600CVE-2024-25600Public

    Unauthenticated Remote Code Execution – Bricks <= 1.9.6

    Python 180 39

  5. CVE-2023-22515CVE-2023-22515Public

    CVE-2023-22515: Confluence Broken Access Control Exploit

    Python 154 32

  6. CVE-2024-45519CVE-2024-45519Public

    Zimbra - Remote Command Execution (CVE-2024-45519)

    Python 139 24

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
View Chocapikk's full-sized avatar
👻
👻

Highlights

  • Pro

Block or report Chocapikk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chocapikk/README.md

Valentin Lobstein

Security Researcher & Exploit Developer @ VulnCheck (@vlobstein-vc)

Just a guy who likes breaking stuff. Can't stop looking for bugs. Sometimes I forget to breathe.

Blog · Twitter · LinkedIn · Ko-fi


84 CVEs · 6 on VulnCheck KEV · Referenced by CERT-FR & BSI


Notable Research

CVETargetImpactRef
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla)Unauth RCE via PHP object injection + XOR keystream recoveryVulnCheck · Blog
CVE-2026-60105Monsta FTPUnauth SSRF via IPv4-mapped IPv6 blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBillingDup SSTI escalated to full RCE via getDi()VulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3CUnauth RCE via pickle deserializationVulnCheck · Blog
CVE-2026-29059Windmill + Nextcloud FlowUnauth RCE chain (5 stages)CERT-FR · BSI · Blog
CVE-2026-39912Xboard / V2Board (7k+ instances)Unauth account takeover via token leakBlog · Exploit
CVE-2026-28515..17openDCIMUnauth RCE (3 chained vulns)VKEV · VKEV · Blog
CVE-2026-27760OpenCATSUnauth RCE via installer code injectionVKEV
CVE-2026-29514NetBoxLow-priv RCE via Jinja2 sandbox bypassBlog · PR
CVE-2025-2611ICTBroadcastUnauth RCE via cookie injectionVKEV · Blog
CVE-2025-34147..52Aitemi M300 WiFi Repeater6 unauth command injectionsCERT-FR · Blog
CVE-2024-22899..03Vinchin Backup & RecoveryExploit chainExploit
All CVEs (84)
CVEDescriptionLinks
CVE-2026-73373Joomla! Core: unrestricted upload of SHTML files leading to code execution (1.0.0-5.4.7, 6.0.0-6.1.2)NVD
CVE-2026-14863FileRun: auth RCE via OS command injection in thumbnail generation (ffmpeg/ImageMagick)Advisory · Blog
CVE-2026-66732 & CVE-2026-66733Sonic 3 A.I.R.: missing source address validation + unbounded memory allocation DoSAdvisory
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla): unauth PHP object injection via XOR keystream recovery, RCE on Joomla 3.9-5.2.1VulnCheck · Blog
CVE-2026-60105Monsta FTP: unauth SSRF via IPv4-mapped IPv6 (::ffff:) blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBilling: SSTI to RCE via getDi() DI container (PDO access) in unsandboxed Twig rendering - VulnCheck KEVVulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3C: unauth RCE via pickle.loads() deserialization in inference APIVulnCheck · Blog
CVE-2026-29514NetBox: low-priv RCE via Jinja2 SandboxedEnvironment bypass in ExportTemplateBlog · PR
CVE-2026-29059Windfall: unauth path traversal + file read in Windmill & Nextcloud Flow - VulnCheck KEV - CERT-FRBlog · Toolkit · CERT-FR
CVE-2026-23696Windmill SQLi in folder management to JWT secret leak to token forge to RCEBlog
CVE-2026-22683Windmill operator role bypass: operators can create/execute scripts despite documentationBlog
CVE-2026-39912Unauth account takeover in Xboard & V2BoardBlog · Exploit
CVE-2026-28515 to CVE-2026-285173 chained vulns in openDCIM: unauth RCE on Docker - 28515 & 28517 on VulnCheck KEVBlog · Exploit
CVE-2026-27760PHP code injection in OpenCATS installer AJAX endpoint - VulnCheck KEVBlog · VulnCheck
CVE-2026-27743 to CVE-2026-277475 vulns in SPIP plugins: 2 SQLi, 2 RCE, 1 XSSBlog
CVE-2026-27174 to CVE-2026-271818 vulns in MajorDoMo: 3 RCE, SQLi, 3 XSSBlog
CVE-2026-25874Unauth RCE via Pickle in HuggingFace LeRobot (21.5k stars)Blog
CVE-2026-25873Unauth RCE via Pickle in OmniGen2 reward serverBlog
CVE-2026-29023Hard-coded API key in Keygraph Shannon routerNVD
CVE-2026-26210Unauth RCE via Pickle in KTransformers (16.5k stars)Blog · Fix PR
CVE-2026-26220Unauth RCE via Pickle in LightLLMBlog
CVE-2026-26215Unauth RCE via Pickle in manga-image-translatorBlog · VulnCheck
CVE-2025-34433Unauth RCE in AVideo via predictable installation saltBlog · VulnCheck
CVE-2025-34434 to CVE-2025-344429 additional vulns in AVideo: IDORs, open redirects, info disclosureBlog
CVE-2025-34452Path Traversal + SSRF in StreamaBlog · VulnCheck
CVE-2025-34147 to CVE-2025-341526 unauth command injections in Aitemi M300 - CERT-FRPart 1 · Part 2 · CERT-FR
CVE-2025-30007 & CVE-2025-30008Unauth XSS in Vembu BDRSuiteBlog
CVE-2025-2611ICTBroadcast unauth RCE - VulnCheck KEVGitHub · VulnCheck KEV
CVE-2025-2609 & CVE-2025-2610Stored XSS in MagnusBillingBlog · VulnCheck
CVE-2025-2292, CVE-2025-30004 to CVE-2025-30006Auth vulns in Xorcom CompletePBXVulnCheck
CVE-2024-31819Unauth RCE in AVideoGitHub
CVE-2024-35373 & CVE-2024-353742 unauth RCE in MocodoBlog
CVE-2024-30920 to CVE-2024-30929, CVE-2024-31818Research in DerbyNetGitHub
CVE-2024-22899 to CVE-2024-22903, CVE-2024-25228Exploit chain in Vinchin Backup & RecoveryGitHub
CVE-2024-3032Themify Builder Open RedirectWPScan
CVE-2023-50917RCE in MajorDoMoGitHub

Tools

ToolDescription
wpprobeFast WordPress plugin enumeration (930+ stars) - in Kali, BlackArch, NixOS, Exegol
cewlaiAI-powered wordlist generator (CeWL + CUPP + LLM in one binary)
pgreadDump PostgreSQL data from heap files without credentials
LFIHuntScan & exploit Local File Inclusion
msf-exploit-collectionAll my Metasploit modules in one place

Hall of Fame

Ferrari (2023) · Siemens (2024) · Philips (2024) · Wikimedia (2024)

Pinned Loading

  1. wpprobewpprobePublic

    A fast WordPress plugin enumeration tool

    Go 942 124

  2. CVE-2026-21858CVE-2026-21858Public

    n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

    Python 259 51

  3. CVE-2023-29357CVE-2023-29357Public

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Python 238 33

  4. CVE-2024-25600CVE-2024-25600Public

    Unauthenticated Remote Code Execution – Bricks <= 1.9.6

    Python 180 39

  5. CVE-2023-22515CVE-2023-22515Public

    CVE-2023-22515: Confluence Broken Access Control Exploit

    Python 154 32

  6. CVE-2024-45519CVE-2024-45519Public

    Zimbra - Remote Command Execution (CVE-2024-45519)

    Python 139 24

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View Chocapikk's full-sized avatar
👻
👻

Highlights

  • Pro

Block or report Chocapikk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chocapikk/README.md

Valentin Lobstein

Security Researcher & Exploit Developer @ VulnCheck (@vlobstein-vc)

Just a guy who likes breaking stuff. Can't stop looking for bugs. Sometimes I forget to breathe.

Blog · Twitter · LinkedIn · Ko-fi


84 CVEs · 6 on VulnCheck KEV · Referenced by CERT-FR & BSI


Notable Research

CVETargetImpactRef
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla)Unauth RCE via PHP object injection + XOR keystream recoveryVulnCheck · Blog
CVE-2026-60105Monsta FTPUnauth SSRF via IPv4-mapped IPv6 blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBillingDup SSTI escalated to full RCE via getDi()VulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3CUnauth RCE via pickle deserializationVulnCheck · Blog
CVE-2026-29059Windmill + Nextcloud FlowUnauth RCE chain (5 stages)CERT-FR · BSI · Blog
CVE-2026-39912Xboard / V2Board (7k+ instances)Unauth account takeover via token leakBlog · Exploit
CVE-2026-28515..17openDCIMUnauth RCE (3 chained vulns)VKEV · VKEV · Blog
CVE-2026-27760OpenCATSUnauth RCE via installer code injectionVKEV
CVE-2026-29514NetBoxLow-priv RCE via Jinja2 sandbox bypassBlog · PR
CVE-2025-2611ICTBroadcastUnauth RCE via cookie injectionVKEV · Blog
CVE-2025-34147..52Aitemi M300 WiFi Repeater6 unauth command injectionsCERT-FR · Blog
CVE-2024-22899..03Vinchin Backup & RecoveryExploit chainExploit
All CVEs (84)
CVEDescriptionLinks
CVE-2026-73373Joomla! Core: unrestricted upload of SHTML files leading to code execution (1.0.0-5.4.7, 6.0.0-6.1.2)NVD
CVE-2026-14863FileRun: auth RCE via OS command injection in thumbnail generation (ffmpeg/ImageMagick)Advisory · Blog
CVE-2026-66732 & CVE-2026-66733Sonic 3 A.I.R.: missing source address validation + unbounded memory allocation DoSAdvisory
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla): unauth PHP object injection via XOR keystream recovery, RCE on Joomla 3.9-5.2.1VulnCheck · Blog
CVE-2026-60105Monsta FTP: unauth SSRF via IPv4-mapped IPv6 (::ffff:) blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBilling: SSTI to RCE via getDi() DI container (PDO access) in unsandboxed Twig rendering - VulnCheck KEVVulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3C: unauth RCE via pickle.loads() deserialization in inference APIVulnCheck · Blog
CVE-2026-29514NetBox: low-priv RCE via Jinja2 SandboxedEnvironment bypass in ExportTemplateBlog · PR
CVE-2026-29059Windfall: unauth path traversal + file read in Windmill & Nextcloud Flow - VulnCheck KEV - CERT-FRBlog · Toolkit · CERT-FR
CVE-2026-23696Windmill SQLi in folder management to JWT secret leak to token forge to RCEBlog
CVE-2026-22683Windmill operator role bypass: operators can create/execute scripts despite documentationBlog
CVE-2026-39912Unauth account takeover in Xboard & V2BoardBlog · Exploit
CVE-2026-28515 to CVE-2026-285173 chained vulns in openDCIM: unauth RCE on Docker - 28515 & 28517 on VulnCheck KEVBlog · Exploit
CVE-2026-27760PHP code injection in OpenCATS installer AJAX endpoint - VulnCheck KEVBlog · VulnCheck
CVE-2026-27743 to CVE-2026-277475 vulns in SPIP plugins: 2 SQLi, 2 RCE, 1 XSSBlog
CVE-2026-27174 to CVE-2026-271818 vulns in MajorDoMo: 3 RCE, SQLi, 3 XSSBlog
CVE-2026-25874Unauth RCE via Pickle in HuggingFace LeRobot (21.5k stars)Blog
CVE-2026-25873Unauth RCE via Pickle in OmniGen2 reward serverBlog
CVE-2026-29023Hard-coded API key in Keygraph Shannon routerNVD
CVE-2026-26210Unauth RCE via Pickle in KTransformers (16.5k stars)Blog · Fix PR
CVE-2026-26220Unauth RCE via Pickle in LightLLMBlog
CVE-2026-26215Unauth RCE via Pickle in manga-image-translatorBlog · VulnCheck
CVE-2025-34433Unauth RCE in AVideo via predictable installation saltBlog · VulnCheck
CVE-2025-34434 to CVE-2025-344429 additional vulns in AVideo: IDORs, open redirects, info disclosureBlog
CVE-2025-34452Path Traversal + SSRF in StreamaBlog · VulnCheck
CVE-2025-34147 to CVE-2025-341526 unauth command injections in Aitemi M300 - CERT-FRPart 1 · Part 2 · CERT-FR
CVE-2025-30007 & CVE-2025-30008Unauth XSS in Vembu BDRSuiteBlog
CVE-2025-2611ICTBroadcast unauth RCE - VulnCheck KEVGitHub · VulnCheck KEV
CVE-2025-2609 & CVE-2025-2610Stored XSS in MagnusBillingBlog · VulnCheck
CVE-2025-2292, CVE-2025-30004 to CVE-2025-30006Auth vulns in Xorcom CompletePBXVulnCheck
CVE-2024-31819Unauth RCE in AVideoGitHub
CVE-2024-35373 & CVE-2024-353742 unauth RCE in MocodoBlog
CVE-2024-30920 to CVE-2024-30929, CVE-2024-31818Research in DerbyNetGitHub
CVE-2024-22899 to CVE-2024-22903, CVE-2024-25228Exploit chain in Vinchin Backup & RecoveryGitHub
CVE-2024-3032Themify Builder Open RedirectWPScan
CVE-2023-50917RCE in MajorDoMoGitHub

Tools

ToolDescription
wpprobeFast WordPress plugin enumeration (930+ stars) - in Kali, BlackArch, NixOS, Exegol
cewlaiAI-powered wordlist generator (CeWL + CUPP + LLM in one binary)
pgreadDump PostgreSQL data from heap files without credentials
LFIHuntScan & exploit Local File Inclusion
msf-exploit-collectionAll my Metasploit modules in one place

Hall of Fame

Ferrari (2023) · Siemens (2024) · Philips (2024) · Wikimedia (2024)

Pinned Loading

  1. wpprobewpprobePublic

    A fast WordPress plugin enumeration tool

    Go 942 124

  2. CVE-2026-21858CVE-2026-21858Public

    n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

    Python 259 51

  3. CVE-2023-29357CVE-2023-29357Public

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Python 238 33

  4. CVE-2024-25600CVE-2024-25600Public

    Unauthenticated Remote Code Execution – Bricks <= 1.9.6

    Python 180 39

  5. CVE-2023-22515CVE-2023-22515Public

    CVE-2023-22515: Confluence Broken Access Control Exploit

    Python 154 32

  6. CVE-2024-45519CVE-2024-45519Public

    Zimbra - Remote Command Execution (CVE-2024-45519)

    Python 139 24

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View Chocapikk's full-sized avatar
👻
👻

Highlights

  • Pro

Block or report Chocapikk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chocapikk/README.md

Valentin Lobstein

Security Researcher & Exploit Developer @ VulnCheck (@vlobstein-vc)

Just a guy who likes breaking stuff. Can't stop looking for bugs. Sometimes I forget to breathe.

Blog · Twitter · LinkedIn · Ko-fi


84 CVEs · 6 on VulnCheck KEV · Referenced by CERT-FR & BSI


Notable Research

CVETargetImpactRef
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla)Unauth RCE via PHP object injection + XOR keystream recoveryVulnCheck · Blog
CVE-2026-60105Monsta FTPUnauth SSRF via IPv4-mapped IPv6 blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBillingDup SSTI escalated to full RCE via getDi()VulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3CUnauth RCE via pickle deserializationVulnCheck · Blog
CVE-2026-29059Windmill + Nextcloud FlowUnauth RCE chain (5 stages)CERT-FR · BSI · Blog
CVE-2026-39912Xboard / V2Board (7k+ instances)Unauth account takeover via token leakBlog · Exploit
CVE-2026-28515..17openDCIMUnauth RCE (3 chained vulns)VKEV · VKEV · Blog
CVE-2026-27760OpenCATSUnauth RCE via installer code injectionVKEV
CVE-2026-29514NetBoxLow-priv RCE via Jinja2 sandbox bypassBlog · PR
CVE-2025-2611ICTBroadcastUnauth RCE via cookie injectionVKEV · Blog
CVE-2025-34147..52Aitemi M300 WiFi Repeater6 unauth command injectionsCERT-FR · Blog
CVE-2024-22899..03Vinchin Backup & RecoveryExploit chainExploit
All CVEs (84)
CVEDescriptionLinks
CVE-2026-73373Joomla! Core: unrestricted upload of SHTML files leading to code execution (1.0.0-5.4.7, 6.0.0-6.1.2)NVD
CVE-2026-14863FileRun: auth RCE via OS command injection in thumbnail generation (ffmpeg/ImageMagick)Advisory · Blog
CVE-2026-66732 & CVE-2026-66733Sonic 3 A.I.R.: missing source address validation + unbounded memory allocation DoSAdvisory
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla): unauth PHP object injection via XOR keystream recovery, RCE on Joomla 3.9-5.2.1VulnCheck · Blog
CVE-2026-60105Monsta FTP: unauth SSRF via IPv4-mapped IPv6 (::ffff:) blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBilling: SSTI to RCE via getDi() DI container (PDO access) in unsandboxed Twig rendering - VulnCheck KEVVulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3C: unauth RCE via pickle.loads() deserialization in inference APIVulnCheck · Blog
CVE-2026-29514NetBox: low-priv RCE via Jinja2 SandboxedEnvironment bypass in ExportTemplateBlog · PR
CVE-2026-29059Windfall: unauth path traversal + file read in Windmill & Nextcloud Flow - VulnCheck KEV - CERT-FRBlog · Toolkit · CERT-FR
CVE-2026-23696Windmill SQLi in folder management to JWT secret leak to token forge to RCEBlog
CVE-2026-22683Windmill operator role bypass: operators can create/execute scripts despite documentationBlog
CVE-2026-39912Unauth account takeover in Xboard & V2BoardBlog · Exploit
CVE-2026-28515 to CVE-2026-285173 chained vulns in openDCIM: unauth RCE on Docker - 28515 & 28517 on VulnCheck KEVBlog · Exploit
CVE-2026-27760PHP code injection in OpenCATS installer AJAX endpoint - VulnCheck KEVBlog · VulnCheck
CVE-2026-27743 to CVE-2026-277475 vulns in SPIP plugins: 2 SQLi, 2 RCE, 1 XSSBlog
CVE-2026-27174 to CVE-2026-271818 vulns in MajorDoMo: 3 RCE, SQLi, 3 XSSBlog
CVE-2026-25874Unauth RCE via Pickle in HuggingFace LeRobot (21.5k stars)Blog
CVE-2026-25873Unauth RCE via Pickle in OmniGen2 reward serverBlog
CVE-2026-29023Hard-coded API key in Keygraph Shannon routerNVD
CVE-2026-26210Unauth RCE via Pickle in KTransformers (16.5k stars)Blog · Fix PR
CVE-2026-26220Unauth RCE via Pickle in LightLLMBlog
CVE-2026-26215Unauth RCE via Pickle in manga-image-translatorBlog · VulnCheck
CVE-2025-34433Unauth RCE in AVideo via predictable installation saltBlog · VulnCheck
CVE-2025-34434 to CVE-2025-344429 additional vulns in AVideo: IDORs, open redirects, info disclosureBlog
CVE-2025-34452Path Traversal + SSRF in StreamaBlog · VulnCheck
CVE-2025-34147 to CVE-2025-341526 unauth command injections in Aitemi M300 - CERT-FRPart 1 · Part 2 · CERT-FR
CVE-2025-30007 & CVE-2025-30008Unauth XSS in Vembu BDRSuiteBlog
CVE-2025-2611ICTBroadcast unauth RCE - VulnCheck KEVGitHub · VulnCheck KEV
CVE-2025-2609 & CVE-2025-2610Stored XSS in MagnusBillingBlog · VulnCheck
CVE-2025-2292, CVE-2025-30004 to CVE-2025-30006Auth vulns in Xorcom CompletePBXVulnCheck
CVE-2024-31819Unauth RCE in AVideoGitHub
CVE-2024-35373 & CVE-2024-353742 unauth RCE in MocodoBlog
CVE-2024-30920 to CVE-2024-30929, CVE-2024-31818Research in DerbyNetGitHub
CVE-2024-22899 to CVE-2024-22903, CVE-2024-25228Exploit chain in Vinchin Backup & RecoveryGitHub
CVE-2024-3032Themify Builder Open RedirectWPScan
CVE-2023-50917RCE in MajorDoMoGitHub

Tools

ToolDescription
wpprobeFast WordPress plugin enumeration (930+ stars) - in Kali, BlackArch, NixOS, Exegol
cewlaiAI-powered wordlist generator (CeWL + CUPP + LLM in one binary)
pgreadDump PostgreSQL data from heap files without credentials
LFIHuntScan & exploit Local File Inclusion
msf-exploit-collectionAll my Metasploit modules in one place

Hall of Fame

Ferrari (2023) · Siemens (2024) · Philips (2024) · Wikimedia (2024)

Pinned Loading

  1. wpprobewpprobePublic

    A fast WordPress plugin enumeration tool

    Go 942 124

  2. CVE-2026-21858CVE-2026-21858Public

    n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

    Python 259 51

  3. CVE-2023-29357CVE-2023-29357Public

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Python 238 33

  4. CVE-2024-25600CVE-2024-25600Public

    Unauthenticated Remote Code Execution – Bricks <= 1.9.6

    Python 180 39

  5. CVE-2023-22515CVE-2023-22515Public

    CVE-2023-22515: Confluence Broken Access Control Exploit

    Python 154 32

  6. CVE-2024-45519CVE-2024-45519Public

    Zimbra - Remote Command Execution (CVE-2024-45519)

    Python 139 24

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
View Chocapikk's full-sized avatar
👻
👻

Highlights

  • Pro

Block or report Chocapikk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chocapikk/README.md

Valentin Lobstein

Security Researcher & Exploit Developer @ VulnCheck (@vlobstein-vc)

Just a guy who likes breaking stuff. Can't stop looking for bugs. Sometimes I forget to breathe.

Blog · Twitter · LinkedIn · Ko-fi


84 CVEs · 6 on VulnCheck KEV · Referenced by CERT-FR & BSI


Notable Research

CVETargetImpactRef
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla)Unauth RCE via PHP object injection + XOR keystream recoveryVulnCheck · Blog
CVE-2026-60105Monsta FTPUnauth SSRF via IPv4-mapped IPv6 blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBillingDup SSTI escalated to full RCE via getDi()VulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3CUnauth RCE via pickle deserializationVulnCheck · Blog
CVE-2026-29059Windmill + Nextcloud FlowUnauth RCE chain (5 stages)CERT-FR · BSI · Blog
CVE-2026-39912Xboard / V2Board (7k+ instances)Unauth account takeover via token leakBlog · Exploit
CVE-2026-28515..17openDCIMUnauth RCE (3 chained vulns)VKEV · VKEV · Blog
CVE-2026-27760OpenCATSUnauth RCE via installer code injectionVKEV
CVE-2026-29514NetBoxLow-priv RCE via Jinja2 sandbox bypassBlog · PR
CVE-2025-2611ICTBroadcastUnauth RCE via cookie injectionVKEV · Blog
CVE-2025-34147..52Aitemi M300 WiFi Repeater6 unauth command injectionsCERT-FR · Blog
CVE-2024-22899..03Vinchin Backup & RecoveryExploit chainExploit
All CVEs (84)
CVEDescriptionLinks
CVE-2026-73373Joomla! Core: unrestricted upload of SHTML files leading to code execution (1.0.0-5.4.7, 6.0.0-6.1.2)NVD
CVE-2026-14863FileRun: auth RCE via OS command injection in thumbnail generation (ffmpeg/ImageMagick)Advisory · Blog
CVE-2026-66732 & CVE-2026-66733Sonic 3 A.I.R.: missing source address validation + unbounded memory allocation DoSAdvisory
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla): unauth PHP object injection via XOR keystream recovery, RCE on Joomla 3.9-5.2.1VulnCheck · Blog
CVE-2026-60105Monsta FTP: unauth SSRF via IPv4-mapped IPv6 (::ffff:) blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBilling: SSTI to RCE via getDi() DI container (PDO access) in unsandboxed Twig rendering - VulnCheck KEVVulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3C: unauth RCE via pickle.loads() deserialization in inference APIVulnCheck · Blog
CVE-2026-29514NetBox: low-priv RCE via Jinja2 SandboxedEnvironment bypass in ExportTemplateBlog · PR
CVE-2026-29059Windfall: unauth path traversal + file read in Windmill & Nextcloud Flow - VulnCheck KEV - CERT-FRBlog · Toolkit · CERT-FR
CVE-2026-23696Windmill SQLi in folder management to JWT secret leak to token forge to RCEBlog
CVE-2026-22683Windmill operator role bypass: operators can create/execute scripts despite documentationBlog
CVE-2026-39912Unauth account takeover in Xboard & V2BoardBlog · Exploit
CVE-2026-28515 to CVE-2026-285173 chained vulns in openDCIM: unauth RCE on Docker - 28515 & 28517 on VulnCheck KEVBlog · Exploit
CVE-2026-27760PHP code injection in OpenCATS installer AJAX endpoint - VulnCheck KEVBlog · VulnCheck
CVE-2026-27743 to CVE-2026-277475 vulns in SPIP plugins: 2 SQLi, 2 RCE, 1 XSSBlog
CVE-2026-27174 to CVE-2026-271818 vulns in MajorDoMo: 3 RCE, SQLi, 3 XSSBlog
CVE-2026-25874Unauth RCE via Pickle in HuggingFace LeRobot (21.5k stars)Blog
CVE-2026-25873Unauth RCE via Pickle in OmniGen2 reward serverBlog
CVE-2026-29023Hard-coded API key in Keygraph Shannon routerNVD
CVE-2026-26210Unauth RCE via Pickle in KTransformers (16.5k stars)Blog · Fix PR
CVE-2026-26220Unauth RCE via Pickle in LightLLMBlog
CVE-2026-26215Unauth RCE via Pickle in manga-image-translatorBlog · VulnCheck
CVE-2025-34433Unauth RCE in AVideo via predictable installation saltBlog · VulnCheck
CVE-2025-34434 to CVE-2025-344429 additional vulns in AVideo: IDORs, open redirects, info disclosureBlog
CVE-2025-34452Path Traversal + SSRF in StreamaBlog · VulnCheck
CVE-2025-34147 to CVE-2025-341526 unauth command injections in Aitemi M300 - CERT-FRPart 1 · Part 2 · CERT-FR
CVE-2025-30007 & CVE-2025-30008Unauth XSS in Vembu BDRSuiteBlog
CVE-2025-2611ICTBroadcast unauth RCE - VulnCheck KEVGitHub · VulnCheck KEV
CVE-2025-2609 & CVE-2025-2610Stored XSS in MagnusBillingBlog · VulnCheck
CVE-2025-2292, CVE-2025-30004 to CVE-2025-30006Auth vulns in Xorcom CompletePBXVulnCheck
CVE-2024-31819Unauth RCE in AVideoGitHub
CVE-2024-35373 & CVE-2024-353742 unauth RCE in MocodoBlog
CVE-2024-30920 to CVE-2024-30929, CVE-2024-31818Research in DerbyNetGitHub
CVE-2024-22899 to CVE-2024-22903, CVE-2024-25228Exploit chain in Vinchin Backup & RecoveryGitHub
CVE-2024-3032Themify Builder Open RedirectWPScan
CVE-2023-50917RCE in MajorDoMoGitHub

Tools

ToolDescription
wpprobeFast WordPress plugin enumeration (930+ stars) - in Kali, BlackArch, NixOS, Exegol
cewlaiAI-powered wordlist generator (CeWL + CUPP + LLM in one binary)
pgreadDump PostgreSQL data from heap files without credentials
LFIHuntScan & exploit Local File Inclusion
msf-exploit-collectionAll my Metasploit modules in one place

Hall of Fame

Ferrari (2023) · Siemens (2024) · Philips (2024) · Wikimedia (2024)

Pinned Loading

  1. wpprobewpprobePublic

    A fast WordPress plugin enumeration tool

    Go 942 124

  2. CVE-2026-21858CVE-2026-21858Public

    n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

    Python 259 51

  3. CVE-2023-29357CVE-2023-29357Public

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Python 238 33

  4. CVE-2024-25600CVE-2024-25600Public

    Unauthenticated Remote Code Execution – Bricks <= 1.9.6

    Python 180 39

  5. CVE-2023-22515CVE-2023-22515Public

    CVE-2023-22515: Confluence Broken Access Control Exploit

    Python 154 32

  6. CVE-2024-45519CVE-2024-45519Public

    Zimbra - Remote Command Execution (CVE-2024-45519)

    Python 139 24

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View Chocapikk's full-sized avatar
👻
👻

Highlights

  • Pro

Block or report Chocapikk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chocapikk/README.md

Valentin Lobstein

Security Researcher & Exploit Developer @ VulnCheck (@vlobstein-vc)

Just a guy who likes breaking stuff. Can't stop looking for bugs. Sometimes I forget to breathe.

Blog · Twitter · LinkedIn · Ko-fi


84 CVEs · 6 on VulnCheck KEV · Referenced by CERT-FR & BSI


Notable Research

CVETargetImpactRef
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla)Unauth RCE via PHP object injection + XOR keystream recoveryVulnCheck · Blog
CVE-2026-60105Monsta FTPUnauth SSRF via IPv4-mapped IPv6 blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBillingDup SSTI escalated to full RCE via getDi()VulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3CUnauth RCE via pickle deserializationVulnCheck · Blog
CVE-2026-29059Windmill + Nextcloud FlowUnauth RCE chain (5 stages)CERT-FR · BSI · Blog
CVE-2026-39912Xboard / V2Board (7k+ instances)Unauth account takeover via token leakBlog · Exploit
CVE-2026-28515..17openDCIMUnauth RCE (3 chained vulns)VKEV · VKEV · Blog
CVE-2026-27760OpenCATSUnauth RCE via installer code injectionVKEV
CVE-2026-29514NetBoxLow-priv RCE via Jinja2 sandbox bypassBlog · PR
CVE-2025-2611ICTBroadcastUnauth RCE via cookie injectionVKEV · Blog
CVE-2025-34147..52Aitemi M300 WiFi Repeater6 unauth command injectionsCERT-FR · Blog
CVE-2024-22899..03Vinchin Backup & RecoveryExploit chainExploit
All CVEs (84)
CVEDescriptionLinks
CVE-2026-73373Joomla! Core: unrestricted upload of SHTML files leading to code execution (1.0.0-5.4.7, 6.0.0-6.1.2)NVD
CVE-2026-14863FileRun: auth RCE via OS command injection in thumbnail generation (ffmpeg/ImageMagick)Advisory · Blog
CVE-2026-66732 & CVE-2026-66733Sonic 3 A.I.R.: missing source address validation + unbounded memory allocation DoSAdvisory
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla): unauth PHP object injection via XOR keystream recovery, RCE on Joomla 3.9-5.2.1VulnCheck · Blog
CVE-2026-60105Monsta FTP: unauth SSRF via IPv4-mapped IPv6 (::ffff:) blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBilling: SSTI to RCE via getDi() DI container (PDO access) in unsandboxed Twig rendering - VulnCheck KEVVulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3C: unauth RCE via pickle.loads() deserialization in inference APIVulnCheck · Blog
CVE-2026-29514NetBox: low-priv RCE via Jinja2 SandboxedEnvironment bypass in ExportTemplateBlog · PR
CVE-2026-29059Windfall: unauth path traversal + file read in Windmill & Nextcloud Flow - VulnCheck KEV - CERT-FRBlog · Toolkit · CERT-FR
CVE-2026-23696Windmill SQLi in folder management to JWT secret leak to token forge to RCEBlog
CVE-2026-22683Windmill operator role bypass: operators can create/execute scripts despite documentationBlog
CVE-2026-39912Unauth account takeover in Xboard & V2BoardBlog · Exploit
CVE-2026-28515 to CVE-2026-285173 chained vulns in openDCIM: unauth RCE on Docker - 28515 & 28517 on VulnCheck KEVBlog · Exploit
CVE-2026-27760PHP code injection in OpenCATS installer AJAX endpoint - VulnCheck KEVBlog · VulnCheck
CVE-2026-27743 to CVE-2026-277475 vulns in SPIP plugins: 2 SQLi, 2 RCE, 1 XSSBlog
CVE-2026-27174 to CVE-2026-271818 vulns in MajorDoMo: 3 RCE, SQLi, 3 XSSBlog
CVE-2026-25874Unauth RCE via Pickle in HuggingFace LeRobot (21.5k stars)Blog
CVE-2026-25873Unauth RCE via Pickle in OmniGen2 reward serverBlog
CVE-2026-29023Hard-coded API key in Keygraph Shannon routerNVD
CVE-2026-26210Unauth RCE via Pickle in KTransformers (16.5k stars)Blog · Fix PR
CVE-2026-26220Unauth RCE via Pickle in LightLLMBlog
CVE-2026-26215Unauth RCE via Pickle in manga-image-translatorBlog · VulnCheck
CVE-2025-34433Unauth RCE in AVideo via predictable installation saltBlog · VulnCheck
CVE-2025-34434 to CVE-2025-344429 additional vulns in AVideo: IDORs, open redirects, info disclosureBlog
CVE-2025-34452Path Traversal + SSRF in StreamaBlog · VulnCheck
CVE-2025-34147 to CVE-2025-341526 unauth command injections in Aitemi M300 - CERT-FRPart 1 · Part 2 · CERT-FR
CVE-2025-30007 & CVE-2025-30008Unauth XSS in Vembu BDRSuiteBlog
CVE-2025-2611ICTBroadcast unauth RCE - VulnCheck KEVGitHub · VulnCheck KEV
CVE-2025-2609 & CVE-2025-2610Stored XSS in MagnusBillingBlog · VulnCheck
CVE-2025-2292, CVE-2025-30004 to CVE-2025-30006Auth vulns in Xorcom CompletePBXVulnCheck
CVE-2024-31819Unauth RCE in AVideoGitHub
CVE-2024-35373 & CVE-2024-353742 unauth RCE in MocodoBlog
CVE-2024-30920 to CVE-2024-30929, CVE-2024-31818Research in DerbyNetGitHub
CVE-2024-22899 to CVE-2024-22903, CVE-2024-25228Exploit chain in Vinchin Backup & RecoveryGitHub
CVE-2024-3032Themify Builder Open RedirectWPScan
CVE-2023-50917RCE in MajorDoMoGitHub

Tools

ToolDescription
wpprobeFast WordPress plugin enumeration (930+ stars) - in Kali, BlackArch, NixOS, Exegol
cewlaiAI-powered wordlist generator (CeWL + CUPP + LLM in one binary)
pgreadDump PostgreSQL data from heap files without credentials
LFIHuntScan & exploit Local File Inclusion
msf-exploit-collectionAll my Metasploit modules in one place

Hall of Fame

Ferrari (2023) · Siemens (2024) · Philips (2024) · Wikimedia (2024)

Pinned Loading

  1. wpprobewpprobePublic

    A fast WordPress plugin enumeration tool

    Go 942 124

  2. CVE-2026-21858CVE-2026-21858Public

    n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

    Python 259 51

  3. CVE-2023-29357CVE-2023-29357Public

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Python 238 33

  4. CVE-2024-25600CVE-2024-25600Public

    Unauthenticated Remote Code Execution – Bricks <= 1.9.6

    Python 180 39

  5. CVE-2023-22515CVE-2023-22515Public

    CVE-2023-22515: Confluence Broken Access Control Exploit

    Python 154 32

  6. CVE-2024-45519CVE-2024-45519Public

    Zimbra - Remote Command Execution (CVE-2024-45519)

    Python 139 24

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View Chocapikk's full-sized avatar
👻
👻

Highlights

  • Pro

Block or report Chocapikk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chocapikk/README.md

Valentin Lobstein

Security Researcher & Exploit Developer @ VulnCheck (@vlobstein-vc)

Just a guy who likes breaking stuff. Can't stop looking for bugs. Sometimes I forget to breathe.

Blog · Twitter · LinkedIn · Ko-fi


84 CVEs · 6 on VulnCheck KEV · Referenced by CERT-FR & BSI


Notable Research

CVETargetImpactRef
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla)Unauth RCE via PHP object injection + XOR keystream recoveryVulnCheck · Blog
CVE-2026-60105Monsta FTPUnauth SSRF via IPv4-mapped IPv6 blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBillingDup SSTI escalated to full RCE via getDi()VulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3CUnauth RCE via pickle deserializationVulnCheck · Blog
CVE-2026-29059Windmill + Nextcloud FlowUnauth RCE chain (5 stages)CERT-FR · BSI · Blog
CVE-2026-39912Xboard / V2Board (7k+ instances)Unauth account takeover via token leakBlog · Exploit
CVE-2026-28515..17openDCIMUnauth RCE (3 chained vulns)VKEV · VKEV · Blog
CVE-2026-27760OpenCATSUnauth RCE via installer code injectionVKEV
CVE-2026-29514NetBoxLow-priv RCE via Jinja2 sandbox bypassBlog · PR
CVE-2025-2611ICTBroadcastUnauth RCE via cookie injectionVKEV · Blog
CVE-2025-34147..52Aitemi M300 WiFi Repeater6 unauth command injectionsCERT-FR · Blog
CVE-2024-22899..03Vinchin Backup & RecoveryExploit chainExploit
All CVEs (84)
CVEDescriptionLinks
CVE-2026-73373Joomla! Core: unrestricted upload of SHTML files leading to code execution (1.0.0-5.4.7, 6.0.0-6.1.2)NVD
CVE-2026-14863FileRun: auth RCE via OS command injection in thumbnail generation (ffmpeg/ImageMagick)Advisory · Blog
CVE-2026-66732 & CVE-2026-66733Sonic 3 A.I.R.: missing source address validation + unbounded memory allocation DoSAdvisory
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla): unauth PHP object injection via XOR keystream recovery, RCE on Joomla 3.9-5.2.1VulnCheck · Blog
CVE-2026-60105Monsta FTP: unauth SSRF via IPv4-mapped IPv6 (::ffff:) blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBilling: SSTI to RCE via getDi() DI container (PDO access) in unsandboxed Twig rendering - VulnCheck KEVVulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3C: unauth RCE via pickle.loads() deserialization in inference APIVulnCheck · Blog
CVE-2026-29514NetBox: low-priv RCE via Jinja2 SandboxedEnvironment bypass in ExportTemplateBlog · PR
CVE-2026-29059Windfall: unauth path traversal + file read in Windmill & Nextcloud Flow - VulnCheck KEV - CERT-FRBlog · Toolkit · CERT-FR
CVE-2026-23696Windmill SQLi in folder management to JWT secret leak to token forge to RCEBlog
CVE-2026-22683Windmill operator role bypass: operators can create/execute scripts despite documentationBlog
CVE-2026-39912Unauth account takeover in Xboard & V2BoardBlog · Exploit
CVE-2026-28515 to CVE-2026-285173 chained vulns in openDCIM: unauth RCE on Docker - 28515 & 28517 on VulnCheck KEVBlog · Exploit
CVE-2026-27760PHP code injection in OpenCATS installer AJAX endpoint - VulnCheck KEVBlog · VulnCheck
CVE-2026-27743 to CVE-2026-277475 vulns in SPIP plugins: 2 SQLi, 2 RCE, 1 XSSBlog
CVE-2026-27174 to CVE-2026-271818 vulns in MajorDoMo: 3 RCE, SQLi, 3 XSSBlog
CVE-2026-25874Unauth RCE via Pickle in HuggingFace LeRobot (21.5k stars)Blog
CVE-2026-25873Unauth RCE via Pickle in OmniGen2 reward serverBlog
CVE-2026-29023Hard-coded API key in Keygraph Shannon routerNVD
CVE-2026-26210Unauth RCE via Pickle in KTransformers (16.5k stars)Blog · Fix PR
CVE-2026-26220Unauth RCE via Pickle in LightLLMBlog
CVE-2026-26215Unauth RCE via Pickle in manga-image-translatorBlog · VulnCheck
CVE-2025-34433Unauth RCE in AVideo via predictable installation saltBlog · VulnCheck
CVE-2025-34434 to CVE-2025-344429 additional vulns in AVideo: IDORs, open redirects, info disclosureBlog
CVE-2025-34452Path Traversal + SSRF in StreamaBlog · VulnCheck
CVE-2025-34147 to CVE-2025-341526 unauth command injections in Aitemi M300 - CERT-FRPart 1 · Part 2 · CERT-FR
CVE-2025-30007 & CVE-2025-30008Unauth XSS in Vembu BDRSuiteBlog
CVE-2025-2611ICTBroadcast unauth RCE - VulnCheck KEVGitHub · VulnCheck KEV
CVE-2025-2609 & CVE-2025-2610Stored XSS in MagnusBillingBlog · VulnCheck
CVE-2025-2292, CVE-2025-30004 to CVE-2025-30006Auth vulns in Xorcom CompletePBXVulnCheck
CVE-2024-31819Unauth RCE in AVideoGitHub
CVE-2024-35373 & CVE-2024-353742 unauth RCE in MocodoBlog
CVE-2024-30920 to CVE-2024-30929, CVE-2024-31818Research in DerbyNetGitHub
CVE-2024-22899 to CVE-2024-22903, CVE-2024-25228Exploit chain in Vinchin Backup & RecoveryGitHub
CVE-2024-3032Themify Builder Open RedirectWPScan
CVE-2023-50917RCE in MajorDoMoGitHub

Tools

ToolDescription
wpprobeFast WordPress plugin enumeration (930+ stars) - in Kali, BlackArch, NixOS, Exegol
cewlaiAI-powered wordlist generator (CeWL + CUPP + LLM in one binary)
pgreadDump PostgreSQL data from heap files without credentials
LFIHuntScan & exploit Local File Inclusion
msf-exploit-collectionAll my Metasploit modules in one place

Hall of Fame

Ferrari (2023) · Siemens (2024) · Philips (2024) · Wikimedia (2024)

Pinned Loading

  1. wpprobewpprobePublic

    A fast WordPress plugin enumeration tool

    Go 942 124

  2. CVE-2026-21858CVE-2026-21858Public

    n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

    Python 259 51

  3. CVE-2023-29357CVE-2023-29357Public

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Python 238 33

  4. CVE-2024-25600CVE-2024-25600Public

    Unauthenticated Remote Code Execution – Bricks <= 1.9.6

    Python 180 39

  5. CVE-2023-22515CVE-2023-22515Public

    CVE-2023-22515: Confluence Broken Access Control Exploit

    Python 154 32

  6. CVE-2024-45519CVE-2024-45519Public

    Zimbra - Remote Command Execution (CVE-2024-45519)

    Python 139 24

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
View Chocapikk's full-sized avatar
👻
👻

Highlights

  • Pro

Block or report Chocapikk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Chocapikk/README.md

Valentin Lobstein

Security Researcher & Exploit Developer @ VulnCheck (@vlobstein-vc)

Just a guy who likes breaking stuff. Can't stop looking for bugs. Sometimes I forget to breathe.

Blog · Twitter · LinkedIn · Ko-fi


84 CVEs · 6 on VulnCheck KEV · Referenced by CERT-FR & BSI


Notable Research

CVETargetImpactRef
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla)Unauth RCE via PHP object injection + XOR keystream recoveryVulnCheck · Blog
CVE-2026-60105Monsta FTPUnauth SSRF via IPv4-mapped IPv6 blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBillingDup SSTI escalated to full RCE via getDi()VulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3CUnauth RCE via pickle deserializationVulnCheck · Blog
CVE-2026-29059Windmill + Nextcloud FlowUnauth RCE chain (5 stages)CERT-FR · BSI · Blog
CVE-2026-39912Xboard / V2Board (7k+ instances)Unauth account takeover via token leakBlog · Exploit
CVE-2026-28515..17openDCIMUnauth RCE (3 chained vulns)VKEV · VKEV · Blog
CVE-2026-27760OpenCATSUnauth RCE via installer code injectionVKEV
CVE-2026-29514NetBoxLow-priv RCE via Jinja2 sandbox bypassBlog · PR
CVE-2025-2611ICTBroadcastUnauth RCE via cookie injectionVKEV · Blog
CVE-2025-34147..52Aitemi M300 WiFi Repeater6 unauth command injectionsCERT-FR · Blog
CVE-2024-22899..03Vinchin Backup & RecoveryExploit chainExploit
All CVEs (84)
CVEDescriptionLinks
CVE-2026-73373Joomla! Core: unrestricted upload of SHTML files leading to code execution (1.0.0-5.4.7, 6.0.0-6.1.2)NVD
CVE-2026-14863FileRun: auth RCE via OS command injection in thumbnail generation (ffmpeg/ImageMagick)Advisory · Blog
CVE-2026-66732 & CVE-2026-66733Sonic 3 A.I.R.: missing source address validation + unbounded memory allocation DoSAdvisory
CVE-2026-65883Aimy Captcha-Less Form Guard (Joomla): unauth PHP object injection via XOR keystream recovery, RCE on Joomla 3.9-5.2.1VulnCheck · Blog
CVE-2026-60105Monsta FTP: unauth SSRF via IPv4-mapped IPv6 (::ffff:) blocklist bypassVulnCheck · Blog
CVE-2026-28496FOSSBilling: SSTI to RCE via getDi() DI container (PDO access) in unsandboxed Twig rendering - VulnCheck KEVVulnCheck · Blog · Advisory
CVE-2026-53805NVIDIA SIL GEN3C: unauth RCE via pickle.loads() deserialization in inference APIVulnCheck · Blog
CVE-2026-29514NetBox: low-priv RCE via Jinja2 SandboxedEnvironment bypass in ExportTemplateBlog · PR
CVE-2026-29059Windfall: unauth path traversal + file read in Windmill & Nextcloud Flow - VulnCheck KEV - CERT-FRBlog · Toolkit · CERT-FR
CVE-2026-23696Windmill SQLi in folder management to JWT secret leak to token forge to RCEBlog
CVE-2026-22683Windmill operator role bypass: operators can create/execute scripts despite documentationBlog
CVE-2026-39912Unauth account takeover in Xboard & V2BoardBlog · Exploit
CVE-2026-28515 to CVE-2026-285173 chained vulns in openDCIM: unauth RCE on Docker - 28515 & 28517 on VulnCheck KEVBlog · Exploit
CVE-2026-27760PHP code injection in OpenCATS installer AJAX endpoint - VulnCheck KEVBlog · VulnCheck
CVE-2026-27743 to CVE-2026-277475 vulns in SPIP plugins: 2 SQLi, 2 RCE, 1 XSSBlog
CVE-2026-27174 to CVE-2026-271818 vulns in MajorDoMo: 3 RCE, SQLi, 3 XSSBlog
CVE-2026-25874Unauth RCE via Pickle in HuggingFace LeRobot (21.5k stars)Blog
CVE-2026-25873Unauth RCE via Pickle in OmniGen2 reward serverBlog
CVE-2026-29023Hard-coded API key in Keygraph Shannon routerNVD
CVE-2026-26210Unauth RCE via Pickle in KTransformers (16.5k stars)Blog · Fix PR
CVE-2026-26220Unauth RCE via Pickle in LightLLMBlog
CVE-2026-26215Unauth RCE via Pickle in manga-image-translatorBlog · VulnCheck
CVE-2025-34433Unauth RCE in AVideo via predictable installation saltBlog · VulnCheck
CVE-2025-34434 to CVE-2025-344429 additional vulns in AVideo: IDORs, open redirects, info disclosureBlog
CVE-2025-34452Path Traversal + SSRF in StreamaBlog · VulnCheck
CVE-2025-34147 to CVE-2025-341526 unauth command injections in Aitemi M300 - CERT-FRPart 1 · Part 2 · CERT-FR
CVE-2025-30007 & CVE-2025-30008Unauth XSS in Vembu BDRSuiteBlog
CVE-2025-2611ICTBroadcast unauth RCE - VulnCheck KEVGitHub · VulnCheck KEV
CVE-2025-2609 & CVE-2025-2610Stored XSS in MagnusBillingBlog · VulnCheck
CVE-2025-2292, CVE-2025-30004 to CVE-2025-30006Auth vulns in Xorcom CompletePBXVulnCheck
CVE-2024-31819Unauth RCE in AVideoGitHub
CVE-2024-35373 & CVE-2024-353742 unauth RCE in MocodoBlog
CVE-2024-30920 to CVE-2024-30929, CVE-2024-31818Research in DerbyNetGitHub
CVE-2024-22899 to CVE-2024-22903, CVE-2024-25228Exploit chain in Vinchin Backup & RecoveryGitHub
CVE-2024-3032Themify Builder Open RedirectWPScan
CVE-2023-50917RCE in MajorDoMoGitHub

Tools

ToolDescription
wpprobeFast WordPress plugin enumeration (930+ stars) - in Kali, BlackArch, NixOS, Exegol
cewlaiAI-powered wordlist generator (CeWL + CUPP + LLM in one binary)
pgreadDump PostgreSQL data from heap files without credentials
LFIHuntScan & exploit Local File Inclusion
msf-exploit-collectionAll my Metasploit modules in one place

Hall of Fame

Ferrari (2023) · Siemens (2024) · Philips (2024) · Wikimedia (2024)

Pinned Loading

  1. wpprobewpprobePublic

    A fast WordPress plugin enumeration tool

    Go 942 124

  2. CVE-2026-21858CVE-2026-21858Public

    n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

    Python 259 51

  3. CVE-2023-29357CVE-2023-29357Public

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

    Python 238 33

  4. CVE-2024-25600CVE-2024-25600Public

    Unauthenticated Remote Code Execution – Bricks <= 1.9.6

    Python 180 39

  5. CVE-2023-22515CVE-2023-22515Public

    CVE-2023-22515: Confluence Broken Access Control Exploit

    Python 154 32

  6. CVE-2024-45519CVE-2024-45519Public

    Zimbra - Remote Command Execution (CVE-2024-45519)

    Python 139 24