



Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

PoC script for HTTP/2 Rapid Reset (CVE-2023-44487) that sends crafted HTTP/2 streams to trigger denial-of-service conditions on vulnerable servers,…

Proof-of-concept for CVE-2026-19500, a DoS vulnerability in the SureForms WordPress plugin that exhausts server resources via oversized key-value…

PoC for a Path Traversal vulnerability in Whistle v2.9.98 via the /cgi-bin/sessions/get-temp-file endpoint. (Unpatched)

Exploit for CVE-2024-38856 affecting Apache OFBiz versions before 18.12.15

Exploits CVE-2026-64849 in MLflow, providing a proof-of-concept attack for security researchers to validate vulnerable deployments.

Proof-of-concept exploits for CVE-2026-56197 demonstrating remote code execution in Windows Admin Center, implemented in Python for vulnerability…

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

Python PoC validating unauthenticated BookingPress Pro REST API exposure and checking for exposed booking/customer data with configurable request…

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

Proof-of-concept exploit for the Apache Struts JSON plugin denial-of-service vulnerability (CVE-2026-73633), demonstrating CPU and memory exhaustion…

WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload

This experimetal fuzzer is meant to be used for API in-memory fuzzing.