
CVE-2026-70376
Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Technical CVE write-up detailing missing brute-force protection in a web admin login form, with PoC reproduction, attack-chain context, and…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Curated RDP Wireshark captures illustrating Kerberos, NTLM, smartcard, NLA, Restricted Admin, Credential Guard, RD Gateway, and clipboard redirection…

Exploit PoC for CVE-2026-64638 demonstrating WordPress pre-auth XSS to RCE. Captures an admin Application Password, publishes a page, uploads a…

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

Deliberately vulnerable Next.js lab demonstrating CVE-2025-29927 middleware authorization bypass. Includes Dockerized app, middleware-protected admin…

Exploits Hikvision CVE-2017-7921 to demonstrate unauthenticated credential disclosure and admin interface exposure, promoting patches and secure…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Exploit for SQL injection in WordPress Video Gallery plugin (version 2.3.6) via orderby parameter, enabling unauthenticated database extraction.

TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

Simulates camera permission phishing attacks for security awareness training, featuring realistic templates, an admin dashboard, and real-time alerts…

Functional proof-of-concept for CVE-2022-47447, a Cross-Site Request Forgery (CSRF) vulnerability in a WordPress plugin, targeting authenticated…

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…