
CVE-2023-43144
Assets Management System 1.0 is vulnerable to SQL injection via the id parameter in delete.php

Assets Management System 1.0 is vulnerable to SQL injection via the id parameter in delete.php

Java library for XML serialization and deserialization, with a focus on CVE-2020-26217 exploitation. Enables converting Java objects to XML and back,…

CVE-2018-6574 go get

CVE-2021-44228

CVE-2024-29399 reference

Proof of concept for CVE-2016-4463

Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java…

Go-based proof-of-concept exploit for CVE-2018-6574, demonstrating directory traversal in Go's net/http package for security testing and…

CVE-2018-6574 go get RCE

nameko Arbitrary code execution due to YAML deserialization

Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a craftedpayload to the…

CSV Injection exists in InterMind iMind Server through 3.13.65 via the csv export functionality.

Proof-of-concept exploit for CVE-2024-32004, a Git remote code execution vulnerability, demonstrating exploitation via a malicious upload-pack filter.

Exploit for CVE-2019-3396, a path traversal and RCE vulnerability in Confluence Server, enabling unauthorized file read and remote code execution.

Proof-of-concept exploit for CVE-2023-33733, demonstrating remote code execution in the Reportlab library via crafted PDF generation.

Proof-of-concept exploit for CVE-2018-6574, a Go package vulnerability allowing arbitrary code execution via crafted import paths.

Exploit script for CVE-2024-34102, an XXE vulnerability in Adobe Commerce allowing arbitrary code execution via crafted XML documents.

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's 'go get' command. Demonstrates exploitation via malicious…