
CVE-2023-42222
Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

CVE-2022-1388

Proof-of-concept exploit for CVE-2026-41940, an authentication bypass in cPanel & WHM, enabling unauthenticated access to the control panel.

Exploit for Drupal CVE-2018-7602 remote code execution vulnerability via double URL encoding bypass of sanitize() filter. Includes Docker-based lab…

react2shell PoC with Go / CVE-2025-55182

Python exploit script for CVE-2022-25581 (ClassCMS 2.4 arbitrary file download) that automates login, CSRF token extraction, malicious zip upload…

A PoC for demonstrating CVE-2026-25604

Multi-threaded Python PoC scanner for CVE-2023-49103 that checks large URL lists for exposed phpinfo() output with .htaccess bypass via /.css path…

Proof-of-concept exploit for CVE-2023-41080, demonstrating URL validation bypass in Apache Tomcat to redirect users to arbitrary external sites via…

F5 BIG-IP iControl REST身份验证绕过漏洞

Powertek PDU身份绕过

Analyzes CVE-2025-60423, an authentication bypass in JEECG versions 7.2.8 and 7.2.9, detailing path traversal and URL encoding techniques to bypass…

Python-based exploit for CVE-2022-1388, an F5 BIG-IP iControl REST authentication bypass leading to remote code execution. Supports single URL,…

Proof-of-concept for CVE-2022-45599: PHP type juggling vulnerability in Aztech WMB250AC router login.php allowing admin authentication bypass via…

Proof-of-concept exploit for CVE-2021-42013, demonstrating path traversal and remote code execution on Apache 2.4.50 via double URL encoding bypass…

Better version of rastating.github.io/bludit-brute-force-mitigation-bypass/

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…