
CVE-2025-5304
PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation

PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation
Exploit for CVE-2021-43857 in Gerapy v0.9.7, providing a reverse shell via authenticated project creation and command injection.

Proof-of-concept exploit for CVE-2023-5966, an arbitrary file upload vulnerability in EspoCRM 2.7.4 and earlier, enabling remote code execution via a…

Netdata ndsudo PoC

Proof-of-concept for CVE-2025-29927 that bypasses Next.js middleware authentication by sending a crafted x-middleware-subrequest header to protected…

WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload

Proof-of-concept exploit for CVE-2024-51358, a server-side request forgery (SSRF) vulnerability in Heimdall 2.6.1, enabling remote HTTP requests to…

Tatsu Plugin ZIP File add_custom_font unrestricted upload

Stored Cross-Side Scripting (XSS) leads to privilege escalation in SilverPeas social-networking portal

Proof-of-concept for CVE-2020-24033: Cross-Site Request Forgery on fs.com S3900 24T4S switch allows unauthenticated admin account creation via…

Zoo Management System 1.0 - Stored Cross-Site-Scripting (XSS)

CVE-2024-45264

RiteCMS 3.0 is affected by a Multiple Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload…

CVE-2016-1240 exploit and patch

Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the SITE from…

CVE-2021-41773 Shodan scanner

Proof-of-concept for CVE-2020-9332, a local privilege escalation in FabulaTech USB for Remote Desktop and USB over Network via a controlled software…