
CVE-2024-38856-ApacheOfBiz
Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15
Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15

Exploit for CVE-2024-4040 affecting CrushFTP server in all versions before 10.7.1 and 11.1.0 on all platforms

Exploit for CVE-2024-4879 affecting Vancouver, Washington DC Now and Utah Platform releases

Exploit for CVE-2024-4956 affecting all previous Sonatype Nexus Repository 3.x OSS/Pro versions up to and including 3.68.0

Proof-of-concept for stored cross-site scripting in Redaxo's mediapool (CVE-2024-50803), demonstrating malicious SVG upload on versions below 5.18.0…

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Educational repository for documenting and testing CVE proof-of-concept exploits inside isolated labs, virtual machines, and authorized penetration…

Exploits CVE-2026-64849 in MLflow, providing a proof-of-concept attack for security researchers to validate vulnerable deployments.

Proof-of-concept exploits for CVE-2026-56197 demonstrating remote code execution in Windows Admin Center, implemented in Python for vulnerability…

Multithreaded Python scanner for CVE-2026-15826 and CVE-2026-15748; checks target lists, supports verbose logging, configurable threads, and custom…

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

Study of CVE-2018-6341 in React, demonstrating AI-assisted vulnerability detection, root-cause analysis, and remediation guidance for JavaScript…

Audits GitLab projects against the CIS GitLab Benchmark via read-only API checks, generating JSON reports on compliance and hardening recommendations.

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

Provides PowerShell and batch scripts to back up, restore, and adjust Access Control Lists (ACLs) mitigating PrintNightmare Print Spooler…

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart

Reproduces a stack-exhaustion denial-of-service in deepmerge-ts before 8.0.0, documents exploitation, and includes a scanner for vulnerable…

Exploits unauthenticated RCE in Apache Gravitino < 1.2.1 via H2 JDBC INIT; hosts SQL/Java payloads, executes commands, and exfiltrates output over…