
Vulns
Collection of public proof-of-concept exploits for multiple CVEs, providing vulnerability demonstration code and references for security research and…

Collection of public proof-of-concept exploits for multiple CVEs, providing vulnerability demonstration code and references for security research and…

Python exploit for CVE-2015-1579 targeting WordPress Slider Revolution <= 4.1.4, allowing remote file disclosure. Usage: python3 xpl.py --url=target.

Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

CVE-2026-41940: detect and exploit cpanel vuln

Fully LLM generated exploit for CVE-2026-31431, written in C

Proof-of-concept exploit for CVE-2021-4034 (PwnKit) that escalates privileges to root on vulnerable Linux systems.

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

Una CTF, in formato DSP-compliant, basata sulla CVE-2025-29927 di nextjs.

Dockerized vulnerable Telnet service for testing CVE-2026-24061, providing a controlled environment for vulnerability validation and security…

Proof-of-concept exploit for CVE-2026-72898, targeting Toucan2 behavior with malformed map options to reproduce the vulnerability and validate…

Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing

POC for PDF JS' CVE-2024-4367 vuln

This repository contains a proof of concept exploit for the AMSI Write Raid 0day Vuln

An implementation of F5's `mcp` protocol, including MitM tooling to sniff traffic while vuln hunting

CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

CVE-2026-53921 – odhcpd Stack Overflow (CVSS 9.8) 🛡️ Vuln detailed and comprehensive Write-Up and Verifier & Multi-exploit for OpenWrt DHCPv6 RCE.…