
CVE-2025-5352
Demonstrates a stored XSS vulnerability in lunary-ai/lunary's Analytics component, where unsanitized NEXT_PUBLIC_CUSTOM_SCRIPT injection leads to…

Demonstrates a stored XSS vulnerability in lunary-ai/lunary's Analytics component, where unsanitized NEXT_PUBLIC_CUSTOM_SCRIPT injection leads to…

Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.

Proof-of-concept exploit demonstrating UMCI bypass in Internet Explorer using JScript and ActiveX to execute arbitrary binaries, targeting Windows…

CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

PHP Object Injection exploit for WP Insightly (CVE-2026-49085). Provides proof-of-concept code to demonstrate and test the vulnerability in affected…

PoC exploit for CVE-2025-59536, a high-severity code injection vulnerability in Claude Code's startup trust dialog, enabling remote exploitation of…

A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)

PHP-based exploit module targeting CVE-2025-67146 and CVE-2025-67147 for automated vulnerability exploitation and security assessment.

Proof-of-concept exploit for CVE-2026-20817, demonstrating the vulnerability with a C-based implementation for security research and testing.

This is POC repo for CVE-2026-48208

Proof-of-concept exploit for CVE-2025-25014: Prototype pollution in Kibana enabling arbitrary code execution via crafted HTTP requests to ML and…

CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit

PoC of CVE-2025-30921

Fork of github.com/spring-projects/spring-data-rest (vulnerable to CVE-2017-8046)

Proof-of-concept exploit for CVE-2023-27363, demonstrating a specific vulnerability with automated exploitation logic for security testing and…

