
CVE-2020-1938
Exploit for CVE-2020-1938 (Ghostcat) enabling file read and remote command execution on vulnerable Apache Tomcat servers via the AJP connector.

Exploit for CVE-2020-1938 (Ghostcat) enabling file read and remote command execution on vulnerable Apache Tomcat servers via the AJP connector.

Automated exploitation tool targeting CMS vulnerabilities in Joomla, WordPress, Drupal, PrestaShop, and OsCommerce with built-in brute-force and…

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

Proof of concept of the SQL injection vulnerability affecting the ZTE MF286R router.

Proof-of-concept demonstrating a vulnerability that disables Microsoft Defender (MsMpEng.exe) by locking a folder and rebooting, with screenshots…

CVE-2026-0073-Android-ADBD-bypass-POC汉化版

Scripts for exploiting MSA-18-0020 (CVE-2018-16854) and MSA-19-0004 (CVE-2019-3847)


CVE-2022-39197 bug fix patch

Exploitations scripts for CVE-2023-42791 and CVE-2024-23666.

An example exploit for CVE-2017-7376

Advisory and proof of concept for CVE-2019-12180, demonstrating arbitrary Groovy code execution in SoapUI and ReadyAPI via malicious project files.

POC for CVE-2025-4404

Unprivileged proof-of-concept for CVE-2026-74586, a Linux kernel SCTP ASCONF use-after-free. Provides a raw-packet trigger, reliability metrics, and…

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

PoC exploit for CVE-2021-40346: HAProxy integer overflow enabling HTTP request smuggling and ACL bypass. Includes analysis, reproduction steps, and…

WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via…