
CVE-2024-25411
A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login

Windows ProfSvc 0day

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

IBM/Lotus Domino exploitation

PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM

Exploit Win10Pcap Driver to enable some Privilege in our process token ( local Privilege escalation )

cve-2024-42327 ZBX-25623

Weblogic Unrestricted File Upload

Apache OfBiz vulns

CVE-2019-19033 description and scripts to check the vulnerability in Jalios JCMS 10 (Authentication Bypass)

CVE-2023-0630 - Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection

Proof-of-concept Python script that enumerates valid ServiceNow user accounts by exploiting the password-reset response discrepancy in CVE-2021-45901.

FreePascal implementation of the vsFTPD 2.3.4 CVE-2011-2523

CVE-2022-0439 - Email Subscribers & Newsletters < 5.3.2 - Subscriber+ Blind SQL injection

CVE-2022-28452

cve-2023-22515的python利用脚本