
CVE-2026-19490
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

Reflected XSS via search GET Parameter in Phoca Download

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

Stack buffer overflow PoC for a hardware wallet USB descriptor parser (CVE-2026-22013), showing return-address overwrite and code execution via…

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Exploit for CVE-2025-64512 to get a reverse shell.

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

Gogs service Exploit and get the root user

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

Proof-of-concept exploit for CVE-2026-37070: an authenticated attacker can read arbitrary uploaded files in Veno File Manager 4.4.9 via a crafted GET…