
Drupalgedon3
POC to test/exploit drupal vulnerability SA-CORE-2018-004 / CVE-2018-7602

POC to test/exploit drupal vulnerability SA-CORE-2018-004 / CVE-2018-7602

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in…

IEEE 802.11 Wi-Fi testing tool for protocol weakness exploitation, including beacon flooding, deauthentication, packet fuzzing, and IDS evasion.…

Injects code into ELF executables post-build

How to spoof the command line when spawning a new process from C#.

POCs to demonstrate CVE-2026-42167 in ProFTPD

CVE-2026-72898

Stored XSS via Location Title in DPCalendar Free

SQL Injection Vulnerability on PhpIPAM v1.4.4

CVE-2025-53547 one of poc code

Stored XSS in Nagios Log Server 2024R1.3.1

Authenticated EL injection exploit for GlassFish/Payara admin console enabling remote command execution via crafted parameters in the virtual server…

Detection scripts for Pi-hole FTLDNS RCE (CVE-2026-35517) via newline injection, including Python scanner and Nmap NSE script for version-based…

CVE-2022-23861: Multiple Stored Cross-Site Scripting in YSoft SafeQ

Proof-of-concept for OS command injection in Curo UC300 IP phone admin panel, demonstrating arbitrary command execution via the IP Addr parameter.

Proof-of-concept demonstrating arbitrary code execution in Orval via malicious OpenAPI fields, with setup, exploit steps, and remediation guidance.

Proof-of-concept for a reflected XSS vulnerability in Sourcecodester Task Reminder System 1.0, demonstrating authenticated remote code execution via…
