
CVE-2024-6460
Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI

Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI

A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak

Benign proof-of-concept for CVE-2026-36227, a path traversal vulnerability in Easy Chat Server 3.1 user registration. Demonstrates unauthorized file…

PoC for Silverpeas <= 6.4.2 Username Enumeration

Python exploit for CVE-2007-2447 in Samba, enabling remote command execution via crafted username. Delivers reverse shell to attacker. For authorized…

Proof-of-concept checker for CVE-2025-11833, allowing security researchers to test vulnerable web applications with configurable credentials and loot…

Exploit for CVE-2025-2304

Exploit for CVE-2024-46987

Educational Docker lab demonstrating Telnet NEW-ENVIRON username injection (CVE-2026-24061) with a Python client and vulnerable server for isolated…

Proof-of-concept exploit for CVE-2020-9496 (Apache OFBiz) with nuclei template integration and step-by-step vulnerable environment setup for security…

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

Setting up POC for CVE-2021-26084

An LDAP injection vulnerability exists in org.yamcs.security.LdapAuthModule. The username parameter is inserted directly into LDAP search filters…

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

Exploit systems using older WinRAR without knowing their username (unlike other projects)