
CVE-2025-50461
Technical Details and Exploit for CVE-2025-50461

Technical Details and Exploit for CVE-2025-50461
Proof-of-concept exploit for Moodle CVE-2024-43425, enabling authenticated RCE via crafted calculated questions. Automates login, token extraction,…

Exploitation de CVE-2022-22980

CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE

Technical disclosure of a critical time-based blind SQL injection vulnerability (CVE-2025-68400) in ChurchCRM, including vulnerable code analysis,…

Exploit for CVE-2025-54123, an authenticated OS command injection in Hoverfly's middleware API, providing check-only, single-command, interactive…

Demonstrates CVE-2023-27524 Broken Object Level Authorization (BOLA) vulnerability with vulnerable and fixed Flask API implementations for security…

Detection scripts, patch checker & hardening guide for CVE-2026-44963 (Veeam B&R RCE)

esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11

Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated Stored Cross-Site Scripting Proof of Concept

Vulnerable ThinkPHP 8.0.4 test environment for CVE-2024-44902 nuclei template validation

Hustle Plugin <= 7.8.3 contains hardcoded HubSpot API credentials in inc/providers/hubspot/hustle-hubspot-api.php

Secure coding project, research on CVE-2019-17498 and implement a player score function written in C.

Cross-chain bridge PoC for CVE-2026-23003: demonstrates message forging via missing origin chain ID using vulnerable Solidity contract and Python…

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.

Proof-of-concept exploit for CVE-2025-32433, enabling unauthenticated remote code execution in Erlang/OTP SSH. Includes Docker setup and reverse…

OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario…