
CVE-2023-22047-Oracle-PeopleSoft-LFI
CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

Reproducer that exploits credential vending before location validation in Apache Polaris Iceberg REST, proving cross-tenant cloud reads and bucket…

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

**CVE-2024-28987** is a critical vulnerability in SolarWinds Web Help Desk (WHD) that allows remote attackers to access sensitive ticket information…

PoC for CVE-2025-54416 tj-actions/branch-names command injection

A technical case study and exploitation analysis of the Authentication Bypass vulnerability in TP-Link TL-WR840N firmware (CVE-2018-12633).

React2Shell Exploitation Tool (CVE-2025-55182)

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

CVE-2025-55182 & CVE-2025-66478 proof of concepts

A Telegram Mass Surveillance Bot in Python

Citrix Bleed 2 PoC Scanner (CVE-2025-5777)

POC to exploit WordPress 5.6-5.7 (PHP 8+) Authenticated XXE Injection.

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

WP SuperBackup <= 2.3.3 - Missing Authorization to Unauthenticated Back-Up File Download

CVE-2024-52317 - Apache Tomcat HTTP/2 Data Leakage Vulnerability

Arbitrary File Read and DoS in vendure-ecommerce exploit