
the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass
Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

A script, written in golang. POC for CVE-2023-25157

Docker-based lab and proof-of-concept exploit for CVE-2025-32463, a sudo chroot local privilege escalation, featuring a vulnerable Ubuntu container…

PoC exploit for CVE-2024-9264: Grafana SQL Expression vulnerability enabling local file inclusion and remote code execution via DuckDB SQL injection.…

Proof-of-concept exploit for CVE-2025-54352, a WordPress vulnerability that leaks titles of private and draft posts. Demonstrates the attack and…

Unauthenticated remote code execution exploit for XWiki SolrSearch (CVE-2025-24893) via Groovy injection in the text parameter, with Docker-based lab…

Docker-based PoC environment for CVE-2018-15133 Laravel APP_KEY unserialization vulnerability. Includes exploit script to verify remote code…

Este script es para uso educativo y en entornos autorizados como HackTheBox. El uso contra sistemas sin permiso explícito es ilegal.

Python PoC script for pgAdmin4 Query Tool RCE (CVE-2025-2945)

Docker-based lab environment and exploit script for CVE-2020-8163, a blind remote code execution vulnerability in Rails versions before 5.0.1 and…

PoC exploit for Nginx integer overflow vulnerability (CVE-2017-7529) enabling out-of-bounds cache read. Includes Docker-based lab environment and…

Exploit script for CVE-2025-49844, a use-after-free vulnerability in Redis Lua scripting enabling remote code execution. Targets specific Redis…

Exploit for Drupal CVE-2018-7602 remote code execution vulnerability via double URL encoding bypass of sanitize() filter. Includes Docker-based lab…

Reproducible Docker-based lab for CVE-2025-54068 in Livewire v3.6.3, including a safe PoC exploit chain script for educational vulnerability analysis.

Docker-based lab demonstrating CVE-2025-58360, a critical unauthenticated XXE injection in GeoServer WMS/OWS services. Includes exploit script for…

Proof-of-concept exploit and detection script for Apache Struts CVE-2024-53677 (S2-067), including a Docker-based vulnerable lab environment for…

Proof-of-concept exploit for CVE-2021-3129 targeting Laravel debug mode remote code execution vulnerability. Includes Docker-based test environment…
