
CVE-2026-38192
pluck-CMS-4.7.20-code-injection-vulnerability

pluck-CMS-4.7.20-code-injection-vulnerability

WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)


Educational examples porting Linux kernel vulnerabilities to Rust, featuring intentionally vulnerable code and exploits for learning kernel security…

Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so…

Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

PoC of CVE-2025-22710

GiveWP PHP Object Injection exploit

GiveWP PHP Object Injection exploit

Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

The code for personally reproducing the corresponding vulnerability

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

Detection for CVE-2025-4427 and CVE-2025-4428

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

Proof-of-concept exploit for CVE-2024-5932, a PHP object injection vulnerability in the GiveWP WordPress plugin, enabling unauthenticated remote code…

Proof of Concept for CVE-2020-14295.

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.