
ARC-Browser-Address-Bar-Spoofing-PoC
Proof-of-concept exploit for CVE-2024-25733 demonstrating address bar spoofing in ARC Browser on iOS/iPadOS using JavaScript-based navigation…

Proof-of-concept exploit for CVE-2024-25733 demonstrating address bar spoofing in ARC Browser on iOS/iPadOS using JavaScript-based navigation…

FlatPress 1.3. is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which…

Vulnerability POC for CVE-2023-34845

Proof-of-concept exploit for CVE-2023-21674, a Windows ALPC vulnerability enabling browser sandbox escape and SYSTEM privilege escalation via kernel…

Checks if your Chrome version is vulnerable to CVE-2025-5419, from the browser

Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js

My proof of concept for CVE-2019 Microsoft-Edge

An attacker can execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or privilege escalation.

Proof-of-concept exploit for CVE-2026-35585, an OS command injection vulnerability in File Browser (versions 2.0.0 to 2.33.1). Includes Python and…

Proof of concept for CVE-2022-1364 against Alibaba's UC Browser

Python implementation/PoC for CVE-2024-40422. Exploits a critical directory traversal vulnerability in Devika v1's /api/get-browser-snapshot endpoint…

CVE-2025-24201 WebKit Vulnerability Detector (PoC)

Bypass Authentication

Exploit for CVE-2022-4262, a Chromium browser vulnerability. Includes references to official bug report, in-the-wild exploit analysis, and root cause…

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Reflected XSS exploit PoC for GLPI (CVE-2024-27914) targeting unauthenticated debug mode. Provides a malicious link to trigger XSS in administrator's…

PIrateRF transforms your Raspberry Pi Zero W into a portable RF signal generator that spawns its own WiFi hotspot. Control everything from FM…