Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-repository — 🐞 Repository of CVE found by OCD people | Kitploit
Tools/GitHubGitHub/orange-cyberdefense/cve-repository
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPapers & ResearchCurated Resources
GitHuborange-cyberdefense/cve-repository

CVE-repository

🐞 Repository of CVE found by OCD people

View Repository
8726161 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

OCD CVE Repository


The content provided in this CVE repository is intended for informational purposes only. The vulnerabilities and associated information documented here are provided "as is" and are not subject to any support. By using this repository, you acknowledge and agree that you are using the information contained herein at your own risk. We will not be liable for any direct, indirect or other kinds of damages.


CVE IDExploitTypeProductAuthor(s)References
[CVE-2025-46816][CVE-2025-46816]-Unauthenticated RCEGoSHSGuilhem RIOUX[Advisory][CVE-2025-46816_pub]
[CVE-2025-32786][CVE-2025-32786][PoC][GLPWNME]Unauthenticated SQLiGLPI (glpiinventory plugin)Guilhem RIOUX-
[CVE-2025-32432][CVE-2025-32432][PoC][CVE-2025-32432_exp]Unauthenticated RCECraft CMSNicolas BOURRAS[Blog][CVE-2025-32432_pub]
[CVE-2025-32104][CVE-2025-32104]-Windows Kernel Arbitrary R/WSangoma Technologies driver pbsdrv.sysJean-Pascal THOMAS-
[CVE-2025-22380][CVE-2025-22380]-Incorrect Access ControlPoweradminGuilhem RIOUX-
[CVE-2025-22379][CVE-2025-22379]-Authenticated SQL injectionPineApp Mail SecureAurelien CHALOT-
[CVE-2025-22378][CVE-2025-22378]-Command injectionAvid Nexis AgentAurelien CHALOT-
[CVE-2024-58136][CVE-2024-58136]-Improper Protection of Alternate PathYii FrameworkNicolas BOURRAS[Blog][CVE-2025-32432_pub]
[CVE-2024-55931][CVE-2024-55931]-Token stored in session storageXerox Workplace SuiteCyril SERVIERES-
[CVE-2024-55930][CVE-2024-55930]-Weak default folder permissionsXerox Workplace SuiteCyril SERVIERES-
[CVE-2024-55929][CVE-2024-55929]-Mail spoofingXerox Workplace SuiteCyril SERVIERES-
[CVE-2024-55928][CVE-2024-55928]-Clear text secrets returned & Remote system secrets in clear textXerox Workplace SuiteCyril SERVIERES-
[CVE-2024-55927][CVE-2024-55927]-Flawed token generation implementation & Hard-coded key implementationXerox Workplace SuiteCyril SERVIERES-
[CVE-2024-55926][CVE-2024-55926]-Arbitrary file upload, deletion and read through header manipulationXerox Workplace SuiteCyril SERVIERES-
[CVE-2024-55925][CVE-2024-55925]-API Security bypass through header manipulationXerox Workplace SuiteCyril SERVIERES-
[CVE-2024-50339][CVE-2024-50339][PoC][GLPWNME]Remote code executionGLPIGuilhem RIOUX[Advisory][CVE-2024-50339_pub] & [Blog][CVE-2024-50339_pub2]
[CVE-2024-40638][CVE-2024-40638][PoC][GLPWNME]SQL Injection (authenticated)GLPIGuilhem RIOUX[Advisory][CVE-2024-40638_pub]
[CVE-2024-37149][CVE-2024-37149][PoC][GLPWNME]Remote code executionGLPIGuilhem RIOUX[Advisory][CVE-2024-37149_pub]
[CVE-2024-29889][CVE-2024-29889][PoC][GLPWNME]SQL Injection (authenticated)GLPIGuilhem RIOUX[Advisory][CVE-2024-29889_pub]
[CVE-2024-23767][CVE-2024-23767][PoC][CVE-2024-23767_poc]Configuration tamperingAnybus X-GatewayClaire VACHEROT[Blog post][CVE-2024-23765_pub]
[CVE-2024-23766][CVE-2024-23766][PoC][CVE-2024-23766_poc]Denial of serviceAnybus X-GatewayClaire VACHEROT[Blog post][CVE-2024-23765_pub]
[CVE-2024-23765][CVE-2024-23765]-Denial of serviceAnybus X-GatewayClaire VACHEROT[Blog post][CVE-2024-23765_pub]
[CVE-2023-44256][CVE-2023-44256][PoC][CVE-2023-44256_poc]SSRFFortinet FortiManager & FortiAnalyzerMickael DORIGNY[Advisory][CVE-2023-44256_poc]
[CVE-2023-44249][CVE-2023-44249]-Authorization bypassFortinet FortiManager & FortiAnalyzerMickael DORIGNY[Advisory][CVE-2023-44249_adv]
[CVE-2023-42787][CVE-2023-42787][PoC][CVE-2023-42787_poc]Unprivileged user, web console CLI accessFortinet FortiManager & FortiAnalyzerMickael DORIGNY[Advisory][CVE-2023-42787_poc]
[CVE-2023-41320][CVE-2023-41320][PoC][CVE-2023-41320_poc]SQLi (update clause)GLPI < 10.1.0Guilhem RIOUX[Advisory][CVE-2023-41320_adv]
[CVE-2023-36626][CVE-2023-36626]-Stored XSSInetnum Gecco v6.00.017Emmanuel CAMPA-
[CVE-2023-36625][CVE-2023-36625]-Unauthenticated RCEMontala ResourcespaceGuilhem RIOUX-
[CVE-2023-33303][CVE-2023-33303]-Insufficient Session ExpirationFortinet FortiEDRKevin CARLI[Advisory][CVE-2023-33303_adv]
[CVE-2023-26469][CVE-2023-26469][PoC][CVE-2023-26469_poc]Path traversalJorani/bbaletGuilhem RIOUX-
[CVE-2023-23565][CVE-2023-23565][PoC][CVE-2023-23565_poc]Local File Inclusion (authenticated)Geomatika IsiGeo Web 6.0Romain PENLOUP-
[CVE-2023-23564][CVE-2023-23564][PoC][CVE-2023-23564_poc]Command injection (authenticated)Geomatika IsiGeo Web 6.0Romain PENLOUP & Guilhem RIOUX-
[CVE-2023-23563][CVE-2023-23563][PoC][CVE-2023-23563_poc]SQL Injection (authenticated)Geomatika IsiGeo Web 6.0Romain PENLOUP-
[CVE-2023-20065][CVE-2023-20065]-Local Privilege EscalationCISCO IOS XE SoftwareMickael DORIGNY & Benoit MALABOEUF[Advisory][CVE-2023-20065_adv]
[CVE-2022-45186][CVE-2022-45186][PoC][CVE-2022-45185_poc]Authenticated Database LeakSuiteCRM <= 7.12.7 (<= 8.2.0)Guilhem RIOUX-
[CVE-2022-45185][CVE-2022-45185][PoC][CVE-2022-45185_poc]Authenticated RCE (arbitrary unserialize)SuiteCRM <= 7.12.7 (<= 8.2.0)Guilhem RIOUX-
[CVE-2022-41573][CVE-2022-41573][PoC][CVE-2022-41573_poc]File UploadOvidentia 8.3Nidal GUEDOUAR-
[CVE-2022-41572][CVE-2022-41572][PoC][CVE-2022-41572_poc]Privilege escalationEyesofnetwork <= 5.3Guilhem RIOUX-
[CVE-2022-41571][CVE-2022-41571][PoC][CVE-2022-41571_poc]Authenticated local file inclusionEyesofnetwork <= 5.3Guilhem RIOUX-
[CVE-2022-41570][CVE-2022-41570][PoC][CVE-2022-41570_poc]Unauthenticated sql injectionEyesofnetwork <= 5.3Guilhem RIOUX-
[CVE-2022-35914][CVE-2022-35914][PoC][CVE-2022-35914_poc]Unauthenticated RCEGLPI (versions < 10.0.3 < 9.5.9 )Cyril SERVIERES[Blog post][CVE-2022-35914_pub]
[CVE-2022-34346][CVE-2022-38346][PoC][CVE-2022-38346_poc]SQL Injection (Authentificated)PMB (version 7.4.1 )Mike HOUZIAUX-
[CVE-2022-34328][CVE-2022-34328][PoC][CVE-2022-34328_poc]XSS (Reflected)PMB (version 7.3.10 )Mike HOUZIAUX-
[CVE-2021-46107][CVE-2021-46107][PoC][CVE-2021-46107_poc]Unauthenticated SSRFLigeo Archives (version < 4.0.78)Guilhem RIOUX-
[CVE-2021-44032][CVE-2021-44032][PoC][CVE-2021-44032_poc]Authentication BypassTP-Link Omada SDN Controler V4.4.4 (Windows)Kevin LEHONGRE-
[CVE-2021-42056][CVE-2021-42056]-Privilege EscalationSafenet Authentication Client (Linux)Wilfried PASCAULT-
[CVE-2021-36355][CVE-2021-36355]-File upload to RCEevolucaire imaging <8.5 (8.2.0.12)Cyril SERVIERES-
[CVE-2020-25287][CVE-2020-25287][PoC][CVE-2020-25287_poc]Authenticated RCEPligg 2.0.3Mike HOUZIAUX-
Download Tool