
CVE-2025-12163
CVE-2025-12163: Stored Cross-Site Scripting in Omnipress WordPress Plugin

CVE-2025-12163: Stored Cross-Site Scripting in Omnipress WordPress Plugin
POCs to demonstrate CVE-2026-42167 in ProFTPD

A PoC for demonstrating CVE-2026-25604

Investigating CVE-2022-36804

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel PBX version 4.0.0-6. This allows an authenticated attacker to inject arbitrary…

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan

SharePoint WebPart Injection Exploit Tool

A Bash-based privilege escalation exploit targeting the `below` system performance monitoring tool. This refurbished exploit leverages a symlink…

An authenticated Stored Cross-site Scripting (XSS) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file…

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full…

During analysis of the ecodotempo.com.br website, a Stored Cross-Site Scripting (XSS) vulnerability was discovered. This vulnerability allows an…

During the analysis of the website ecodotempo.com.br, a Stored Cross-Site Scripting (XSS) vulnerability was discovered. This vulnerability allows an…

Proof-of-concept exploit for CVE-2025-27591, a local privilege escalation in the 'below' system monitor. Demonstrates symlink attack on log file to…

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

Proof-of-concept for a reflected XSS vulnerability in Code-projects Jonnys Liquor 1.0, demonstrating script injection via the search parameter in…