
Wildfire
CVE-2026-39154 · Stored XSS in CometChat JS SDK
Penetration testing methodologies, frameworks, reporting, and automation tools.

CVE-2026-39154 · Stored XSS in CometChat JS SDK
Local privilege escalation exploit for Linux targeting CVE-2026-68138 to elevate privileges from unprivileged users to root on vulnerable systems.

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

Confluence Unauthorized Administrator User Addition Exploitation Script

A security research archive documenting vulnerabilities, technical analysis, and PoC demonstrations.

Educational CVE proof-of-concept repository with lab scripts for reproducing, testing, and analyzing specific vulnerabilities in isolated…

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

Python PoC validating unauthenticated BookingPress Pro REST API exposure and checking for exposed booking/customer data with configurable request…

Proof-of-concept exploit for Apache Struts S2-072 (CVE-2026-73633), demonstrating CPU and memory exhaustion by sending crafted JSON requests to the…

Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)

Python proof-of-concept for CVE-2025-11740; triggers the vulnerability to verify exposure and support remediation in authorized security tests.

Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.

OpenMed < 1.5.2 unauthenticated RCE via PII privacy-filter model loading and trust_remote_code=True

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

POC of CVE-2026-51031 for arbitrary local file read