
Debinject
Inject malicious code into *.debs

POC for PDF JS' CVE-2024-4367 vuln

Weak encryption in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject wireless…

SharePoint WebPart Injection Exploit Tool

Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the…

FlatPress 1.3. is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which…

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

Inject .NET assemblies into an existing process

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

This script is designed for detection of vulnerable servers (CVE-2014-0224.) in a wide range of configurations. It attempts to negotiate using each…

Tests bypasses for CVE-2026-3854 patch, providing a proof-of-concept to validate security fixes.

GDidees CMS 3.9.2 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to…

Webrun <= 3.6.0.42 SQLi

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

A PoC for demonstrating CVE-2026-25604

Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace