
CVE-2023-43317
Vertical Privilege Escalation via Session Storage by Amjad Ali (CVE-2023-43317)

Vertical Privilege Escalation via Session Storage by Amjad Ali (CVE-2023-43317)

MatrixSSL session resume bug

CVE-2025-25965 is a newly discovered CSRF vulnerability in the Phpgurukul Online Banquet Booking System v1.2, allowing remote attackers to change a…

The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of…

TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

A repository containing a PoC exploit for CVE‑2025‑8191 in Swagger UI, leveraging XSS injection to exfiltrate session cookies.

Kage is Graphical User Interface for Metasploit Meterpreter and Session Handler

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw…

OSWE, OSEP, OSED, OSEE


NOVA - Claude Code Protection System against prompt injection attacks

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs


PoC for CVE-2026-2005

Proof Of Concept for te NetScaler Vuln

Technical analysis of the cPanel/WHM auth bypass

Proof-of-concept for CVE-2024-4040 (CrushFTP SSTI -> unauthenticated LFI) in a controlled CS443 lab environment - for educational/authorised use only.