
CVE-2025-13342
PoC for CVE-2025-13342

PoC for CVE-2025-13342
Proof-of-concept checker for CVE-2025-11833, allowing security researchers to test vulnerable web applications with configurable credentials and loot…

PoC for CVE-2025-65271 | Found by me

Based on the x.pl exploit/loader script for CVE-2009-1151

PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation

CVE-2025-15495 - Arbitrary File Upload Leading to Remote Code Execution (RCE)

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass

Wordpress Video Gallery - YouTube Gallery and Vimeo Gallery Plugin SQL Injection

GitHub repository for CVE-2023-3460 POC

Demonstrates the x-middleware-subrequest header bypass in Next.js 13.4.19, allowing unauthorized access to protected routes. Includes setup, normal…

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE


TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

Basic Multiplatform Remote Administration Tool - Xamarin

⚡ Create infinite UAC prompts forcing a user to run as admin ⚡

Comprehensive guide for hardening WordPress installations: covers admin user changes, HTTPS enforcement, plugin security, file permissions, and…

I was presented with a high-severity alert indicating a potential exploit attempt of CVE-2023-22515, a zero-day vulnerability in Atlassian…