Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Vulnerability-Research — Curated repository of vulnerability research write-ups with assigned CVEs, detailing discovered weaknesses, impact, and remediation across various applications. | Kitploit
Tools/GitHubGitHub/cydtseng/vulnerability-research
Vulnerability AnalysisCode AnalysisWeb SecurityPapers & ResearchLearning & EducationCurated Resources
GitHubcydtseng/vulnerability-research

Vulnerability-Research

Curated repository of vulnerability research write-ups with assigned CVEs, detailing discovered weaknesses, impact, and remediation across various applications.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
34 months agoNot yet reviewed

🛡️ Vulnerability Research

Here, I catalog the vulnerabilities I've discovered, the corresponding write-ups containing details of the weaknesses, and insights into their impact and remediation.

🏆 Assigned CVEs

CVE IDVulnerability TitleSeverity/CVSSPublishedWrite-Up
N.A.Microsoft Security Response Center (MSRC) 2026 Q1 Security Researcher Leaderboard #192N/AApr 2026Official Acknowledgements Page
N.A.3 x MSRC Security Researcher Acknowledgment for Microsoft Online ServicesN/AMar 2026Official Acknowledgements Page
CVE-2025-63918wmjordan PDFPatcher <= 1.1.3.4663 Directory Traversal in Image Export Functionality6.2Nov 17, 2025Read the full write-up
CVE-2025-63917wmjordan PDFPatcher <= 1.1.3.4663 XML External Entity (XXE) Injection7.1Nov 17, 2025Read the full write-up
CVE-2025-63916luotengyuan MyScreenTools <= 2.2.1.0 OS Command Injection in GIF Compression Tool8.1Nov 17, 2025Read the full write-up
N.A.Microsoft 365 Copilot For Work: Image Data Exfiltration From SharePointLowMar 22, 2025Read the full write-up
CVE-2025-1548iteachyou Dreamer CMS(梦想家 CMS 内容管理系统)4.1.3 Remote File Inclusion5.1Feb 21, 2025Read the full write-up
CVE-2025-1543iteachyou Dreamer CMS(梦想家 CMS 内容管理系统)4.1.3 Path Traversal5.3Feb 21, 2025Read the full write-up
CVE-2025-1084Mindskip xzs-mysql (武汉思维跳跃科技有限公司 - 学之思开源考试系统) 3.9.0 Cross-Site Request Forgery (CSRF)

🛠️ Acknowledgments

I extend my gratitude to the vendors and security teams who cooperated during the responsible disclosure process. Your dedication to improving application security is invaluable.

Download Tool
3.9
Feb 6, 2025
Read the full write-up
CVE-2025-1083Mindskip xzs-mysql (武汉思维跳跃科技有限公司 - 学之思开源考试系统) 3.9.0 CORS Misconfiguration2.8Feb 6, 2025Read the full write-up
CVE-2025-1082Mindskip xzs-mysql (武汉思维跳跃科技有限公司 - 学之思开源考试系统) 3.9.0 Stored Cross Site Scripting (XSS)3.5Feb 6, 2025Read the full write-up
CVE-2024-13199Mtons mblog 3.5.0 Search Function Reflected Cross Site Scripting (XSS)3.2Jan 8, 2025Read the full write-up
CVE-2024-13198Mtons mblog 3.5.0 Login Observable Response Discrepancy3.4Jan 8, 2025Read the full write-up
CVE-2024-13032Antabot White-Jotter 0.2.2 Server-Side Request Forgery (SSRF)5.1Dec 29, 2024Read the full write-up
CVE-2024-13031Antabot White-Jotter 0.2.2 Reflected Cross-Site Scripting (XSS)5.1Dec 29, 2024Read the full write-up
CVE-2024-13029Antabot White-Jotter 0.2.2 Server-Side Request Forgery (SSRF)5.3Dec 29, 2024Read the full write-up
CVE-2024-13028Antabot White-Jotter 0.2.2 Observable Response Discrepancy6.3Dec 29, 2024Read the full write-up
CVE-2024-12995Ruifang-Tech (上海锐昉科技有限公司) Rebuild 3.8.6 Stored Cross Site Scripting (XSS)5.3Dec 27, 2024Read the full write-up
CVE-2024-12990Ruifang-Tech (上海锐昉科技有限公司) Rebuild 3.8.6 Open Redirect5.3Dec 27, 2024Read the full write-up
CVE-2024-55452Dromara UJCMS <= 9.6.3 Arbitrary URL Redirection Via Block Item Upload5.4Dec 17, 2024Read the full write-up
CVE-2024-55451Dromara UJCMS <= 9.6.3 Authenticated SVG-based Stored Cross Site Scripting (XSS)4.8Dec 17, 2024Read the full write-up
CVE-2024-12665Ruifang-Tech (上海锐昉科技有限公司) Rebuild 3.8.5 Task Comment Attachment Upload Stored Cross Site Scripting (XSS)3.5Dec 16, 2024Read the full write-up
CVE-2024-12664Ruifang-Tech (上海锐昉科技有限公司) Rebuild 3.8.5 Project Task Comment Stored Cross Site Scripting (XSS)3.5Dec 16, 2024Read the full write-up
CVE-2024-12663FunnyZPC mee-admin 1.6 Login Username Observable Response Discrepancy3.7Dec 16, 2024Read the full write-up
CVE-2024-12483Dromara UJCMS <= 9.6.3 User ID /users/id Insecure Direct Object Reference (IDOR)3.7Dec 11, 2024Read the full write-up