
CVE-2020-12629
osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting

osTicket 1.14.1 - Persistent Authenticated Cross-Site Scripting
Exploit for CVE-2025-28915: WordPress ThemeEgg ToolKit arbitrary file upload vulnerability allowing remote Web Shell deployment. Includes…

CVE-2022-37207 POC

Proof-of-concept exploit for CVE-2018-11235, a remote code execution vulnerability in Git submodules. Demonstrates exploitation of malicious…

Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload

Proof-of-concept exploit for CVE-2020-0601 (CurveBall) demonstrating ECC certificate validation bypass to spoof trusted CA and sign arbitrary…

Proof of Concept for CVE-2020-14295.

Partners <= 0.2.0 - Unauthenticated PHP Object Injection

Spring4Shell is a critical RCE vulnerability in the Java Spring Framework and is one of three related vulnerabilities published on March 30

Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

CVE-2018-7600.

CVE-2022-37205 POC

Proof-of-concept exploit demonstrating SQL injection in the Daily Habit Tracker App, enabling unauthorized database access and data extraction.

VRPConnector <= 2.0.1 - Unauthenticated PHP Object Injection

PoC for CVE-2022-21340

Proof-of-concept exploit for CVE-2017-1000117, demonstrating a remote code execution vulnerability in Git.

GPX Viewer <= 2.2.8 - Authenticated (Subscriber+) Arbitrary File Creation

Exploit code for CVE-2020-11989, an Apache Shiro authentication bypass vulnerability, enabling remote attackers to bypass security controls in web…