
CVE-2026-22794-POC
🔴 CVE-2026-22794 - Appsmith Password Reset Account Takeover via Origin Header Injection | PoC Exploit + Nuclei Template

🔴 CVE-2026-22794 - Appsmith Password Reset Account Takeover via Origin Header Injection | PoC Exploit + Nuclei Template

Proof-of-concept exploit for CVE-2023-7028, automating GitLab account takeover via password reset email manipulation. Includes temp-mail integration…

Improper Access Control in Mysterium Node before v1.36.0

CVE-2024–27631 Reference

CVE-2026-23550 - Modular DS WordPress Plugin **Unauthenticated Admin Access**

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

Automated All-in-One OS Command Injection Exploitation Tool

File upload vulnerability scanner and exploitation tool.

A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python

🐶 A curated list of Web Security materials and resources.

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

A drone engineered to autonomously seek out, hack, and wirelessly take full control over any other Parrot or 3DR drones within wireless or flying…

SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.

Exploits the Windows Server 2025 dMSA privilege escalation vulnerability to enumerate writable OUs, escalate to arbitrary domain users, extract…

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

Full unauthenticated RCE proof of concept for Rocket.Chat 3.12.1 CVE-2021-22911

Demonstrates a critical GraphQL batching alias-confusion SQL injection (CVE-2026-5432) with a vulnerable Node.js server and Python exploit for…

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…