
CVE-2021-3395
Proof-of-concept for CVE-2021-3395: authenticated stored XSS in Pryaniki 6.44.3 via arbitrary file upload, triggering JavaScript on attachment view.

Proof-of-concept for CVE-2021-3395: authenticated stored XSS in Pryaniki 6.44.3 via arbitrary file upload, triggering JavaScript on attachment view.

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…

CVE-2019-5418 - File Content Disclosure on Ruby on Rails

CVE-2021-21978 exp

Firefox/Tor Browser 0day exploit analysis (CVE-2024-9680) A UAF in animation timelines leading to RCE. Patched.

A lab demonstration of the log4shell vulnerability: CVE-2021-44228

Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR

Proof-of-concept exploit for CVE-2025-69212: OS command injection in OpenSTAManager's P7M file processing, enabling authenticated remote code…

Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

Proof-of-concept exploit for CVE-2024-37763, an unauthenticated stored XSS in MachForm up to v19, demonstrating payload injection via vulnerable…

CVE-2026-24417 - OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service

CVE-2026-22243 - EGroupware has SQL Injection in Nextmatch Filter Processing

CVE-2025-69215 - OpenSTAManager has an SQL Injection in the Stampe Module

CVE-2026-25514 - FacturaScripts has SQL Injection in Autocomplete Actions

CVE-2026-25513 - FacturaScripts has SQL Injection in API ORDER BY Clause

CVE-2026-24416 - OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module

CVE-2026-23491 - InvoicePlane has Unauthenticated Path Traversal in Guest Controller