Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-repository — 🐞 Repository of CVE found by OCD people | Kitploit
Tools/GitHubGitHub/orange-cyberdefense/cve-repository
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPapers & ResearchCurated Resources
GitHuborange-cyberdefense/cve-repository

CVE-repository

🐞 Repository of CVE found by OCD people

View Repository
87261 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

OCD CVE Repository


The content provided in this CVE repository is intended for informational purposes only. The vulnerabilities and associated information documented here are provided "as is" and are not subject to any support. By using this repository, you acknowledge and agree that you are using the information contained herein at your own risk. We will not be liable for any direct, indirect or other kinds of damages.


CVE IDExploitTypeProductAuthor(s)References
CVE-2025-46816-Unauthenticated RCEGoSHSGuilhem RIOUXAdvisory
CVE-2025-32786PoCUnauthenticated SQLiGLPI (glpiinventory plugin)Guilhem RIOUX-
CVE-2025-32432PoCUnauthenticated RCECraft CMSNicolas BOURRASBlog
CVE-2025-32104-Windows Kernel Arbitrary R/WSangoma Technologies driver pbsdrv.sysJean-Pascal THOMAS-
CVE-2025-22380-Incorrect Access ControlPoweradminGuilhem RIOUX-
CVE-2025-22379-Authenticated SQL injectionPineApp Mail SecureAurelien CHALOT-
CVE-2025-22378-Command injectionAvid Nexis AgentAurelien CHALOT-
CVE-2024-58136-Improper Protection of Alternate PathYii FrameworkNicolas BOURRASBlog

Note: the table is sorted by CVE ID.

Download Tool
CVE-2024-55931-Token stored in session storageXerox Workplace SuiteCyril SERVIERES-
CVE-2024-55930-Weak default folder permissionsXerox Workplace SuiteCyril SERVIERES-
CVE-2024-55929-Mail spoofingXerox Workplace SuiteCyril SERVIERES-
CVE-2024-55928-Clear text secrets returned & Remote system secrets in clear textXerox Workplace SuiteCyril SERVIERES-
CVE-2024-55927-Flawed token generation implementation & Hard-coded key implementationXerox Workplace SuiteCyril SERVIERES-
CVE-2024-55926-Arbitrary file upload, deletion and read through header manipulationXerox Workplace SuiteCyril SERVIERES-
CVE-2024-55925-API Security bypass through header manipulationXerox Workplace SuiteCyril SERVIERES-
CVE-2024-50339PoCRemote code executionGLPIGuilhem RIOUXAdvisory & Blog
CVE-2024-40638PoCSQL Injection (authenticated)GLPIGuilhem RIOUXAdvisory
CVE-2024-37149PoCRemote code executionGLPIGuilhem RIOUXAdvisory
CVE-2024-29889PoCSQL Injection (authenticated)GLPIGuilhem RIOUXAdvisory
CVE-2024-23767PoCConfiguration tamperingAnybus X-GatewayClaire VACHEROTBlog post
CVE-2024-23766PoCDenial of serviceAnybus X-GatewayClaire VACHEROTBlog post
CVE-2024-23765-Denial of serviceAnybus X-GatewayClaire VACHEROTBlog post
CVE-2023-44256PoCSSRFFortinet FortiManager & FortiAnalyzerMickael DORIGNYAdvisory
CVE-2023-44249-Authorization bypassFortinet FortiManager & FortiAnalyzerMickael DORIGNYAdvisory
CVE-2023-42787PoCUnprivileged user, web console CLI accessFortinet FortiManager & FortiAnalyzerMickael DORIGNYAdvisory
CVE-2023-41320PoCSQLi (update clause)GLPI < 10.1.0Guilhem RIOUXAdvisory
CVE-2023-36626-Stored XSSInetnum Gecco v6.00.017Emmanuel CAMPA-
CVE-2023-36625-Unauthenticated RCEMontala ResourcespaceGuilhem RIOUX-
CVE-2023-33303-Insufficient Session ExpirationFortinet FortiEDRKevin CARLIAdvisory
CVE-2023-26469PoCPath traversalJorani/bbaletGuilhem RIOUX-
CVE-2023-23565PoCLocal File Inclusion (authenticated)Geomatika IsiGeo Web 6.0Romain PENLOUP-
CVE-2023-23564PoCCommand injection (authenticated)Geomatika IsiGeo Web 6.0Romain PENLOUP & Guilhem RIOUX-
CVE-2023-23563PoCSQL Injection (authenticated)Geomatika IsiGeo Web 6.0Romain PENLOUP-
CVE-2023-20065-Local Privilege EscalationCISCO IOS XE SoftwareMickael DORIGNY & Benoit MALABOEUFAdvisory
CVE-2022-45186PoCAuthenticated Database LeakSuiteCRM <= 7.12.7 (<= 8.2.0)Guilhem RIOUX-
CVE-2022-45185PoCAuthenticated RCE (arbitrary unserialize)SuiteCRM <= 7.12.7 (<= 8.2.0)Guilhem RIOUX-
CVE-2022-41573PoCFile UploadOvidentia 8.3Nidal GUEDOUAR-
CVE-2022-41572PoCPrivilege escalationEyesofnetwork <= 5.3Guilhem RIOUX-
CVE-2022-41571PoCAuthenticated local file inclusionEyesofnetwork <= 5.3Guilhem RIOUX-
CVE-2022-41570PoCUnauthenticated sql injectionEyesofnetwork <= 5.3Guilhem RIOUX-
CVE-2022-35914PoCUnauthenticated RCEGLPI (versions < 10.0.3 < 9.5.9 )Cyril SERVIERESBlog post
CVE-2022-34346PoCSQL Injection (Authentificated)PMB (version 7.4.1 )Mike HOUZIAUX-
CVE-2022-34328PoCXSS (Reflected)PMB (version 7.3.10 )Mike HOUZIAUX-
CVE-2021-46107PoCUnauthenticated SSRFLigeo Archives (version < 4.0.78)Guilhem RIOUX-
CVE-2021-44032PoCAuthentication BypassTP-Link Omada SDN Controler V4.4.4 (Windows)Kevin LEHONGRE-
CVE-2021-42056-Privilege EscalationSafenet Authentication Client (Linux)Wilfried PASCAULT-
CVE-2021-36355-File upload to RCEevolucaire imaging <8.5 (8.2.0.12)Cyril SERVIERES-
CVE-2020-25287PoCAuthenticated RCEPligg 2.0.3Mike HOUZIAUX-
CVE-2020-17454PoCSelf XSSWSO2 API Manager: 3.1.0 or earlierZakaria BRAHIMIAdvisory
CVE-2020-14950PoCAuthenticated RCEaapanel 6.6.6Mike HOUZIAUX-
CVE-2020-14462PoCAuthenticated reflected XSSCaldera 2.7.0Aurélien CHALOT-
CVE-2020-14421PoCAuthenticated RCEaapanel 6.6.6Mike HOUZIAUX-
CVE-2020-14295PoCAuthenticated RCE (from SQLi)cacti (1.2.7, 1.2.12)Cyril SERVIERESAdvisory
CVE-2020-14146PoCXSS (Reflected)KumbiaPHP 1.1.1Mike HOUZIAUX-
CVE-2020-11712PoCXSS (Reflected)Openupload 0.4.3Mike HOUZIAUX-
CVE-2020-10787PoCRoot EoPVestaCP 0.9.8-26Alexandre ZANNIPost
CVE-2020-10786PoCAuthenticated RCEVestaCP 0.9.8-26Alexandre ZANNIPost
CVE-2020-10220PoCUnauthenticated SQLirConfig < 3.9.4Jean-Pascal THOMASBlog post
CVE-2020-8776
CVE-2020-8777
CVE-2020-8778
PoCStored XSSAlfresco 5.2.4Alexandre ZANNI & Romain LOISELPost
CVE-2020-1949PoCReflected XSSSling CMS App 0.14.0 and previous releasesGuillaume GRABÉAdvisory
CVE-2019-19585PoCRoot LPErConfig < 3.9.4Jean-Pascal THOMASBlog post
CVE-2019-19509PoC & MSFAuthenticated RCErConfig < 3.9.4Jean-Pascal THOMASBlog post
CVE-2019-15253PoCStored XSSCisco DNAC 1.3Dylan GARNAUD & Benoit MALABOEUFAdvisory
CVE-2019-13029PoCStored XSSREDCap 8.10/9.1Alexandre ZANNI & Dylan GARNAUDPost