
CVE-2023-31719
Proof-of-concept exploit for CVE-2023-31719, demonstrating SQL injection in the FUXA web application's /api/signin endpoint via a crafted JSON…

Proof-of-concept exploit for CVE-2023-31719, demonstrating SQL injection in the FUXA web application's /api/signin endpoint via a crafted JSON…

Proof-of-concept for a stored Cross-Site Scripting (XSS) vulnerability in Sourcecodester Best Courier Management System v1.0 via the change username…

Proof-of-concept for CVE-2021-39377, a SQL injection vulnerability in openSIS 8.0 via the username parameter, enabling database takeover through…

Proof-of-concept for stored cross-site scripting (XSS) vulnerability in D-Link DSL-2730E routers via the username parameter on the maintenance…

PoC Exploit for CVE-2025-7753 — Time-Based SQL Injection in Online Appointment Booking System 1.0 via the username parameter. Exploit written in C…

Proof-of-concept exploit for CVE-2024-55099, demonstrating SQL injection in the Online Nurse Hiring System v1.0 via unsanitized username parameter,…

Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473

Exploit script for CVE-2019-2618, a Weblogic arbitrary file upload vulnerability, with JSP webshell deployment and encrypted credential decryption.

An unauthenticated PoC for CVE-2020-0796

OpenSSH 7.7 - Username Enumeration

CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability

Exploit for Joomla 3.4.4 - 3.6.4 (CVE-2016-8869 and CVE-2016-8870)

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

Authentication bypass exploit for Joomla CVE-2023-23752 that leaks administrator credentials and MySQL configuration from vulnerable versions…

PowerShell proof-of-concept exploit for CVE-2023-24055 that extracts cleartext passwords from KeePass by abusing trigger functionality and dumping…

Python Exploit for CVE: 2018-9276

Unauthenticated time-based blind SQL injection PoC for VICIdial CVE-2024-8503, with metadata extraction, resumable scans, and strict safety limits.

Proof-of-concept exploit for CVE-2024-44349, an SQL injection in Anteeo WMS v4.7.x, enabling database dumping and arbitrary SQL query execution.