
CVE-2022-48311
HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B HTTP configuration page Cross Site Scripting (XSS)…
Tools for testing, exploiting, and securing web applications and APIs.

HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B HTTP configuration page Cross Site Scripting (XSS)…

TOTOLINK-A702R-V1.0.0-B20161227.1023 Directory Indexing Vulnerability

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 Cross Site Scripting (XSS) Vulnerability

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session

PoC for CVE-2017-17562 written in bash

Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.

a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.

Command Injection in Tenda AC20 16.03.08.12 (/goform/telnet)

Sql injection in itsourcecode Online Tour and Travel Management System 1.0.

PoC to inject a command via the DEVICE_PING endpoint

PoC exploit for CVE-2025-7766 – XXE vulnerability leading to potential RCE.

Proof‑of‑Concept exploits the Full Path Disclosure bug in the “Birth Chart Compatibility” WordPress plugin (<=v2.0)

Exploit Path Traversal in esm-dev

💣 Wordpress WooCommerce users dump exploit.

CVE-2026-53571 `server.fs.deny` bypass on Windows alternate paths PoC.

.NET console application that exploits CVE-2018-9995 vulnerability

Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's…

Orchestration component of purpleteam