
CVE-2022-30507-PoC
PoC for Arbitrary Code Execution in Notable

PoC for Arbitrary Code Execution in Notable

CVE-2026-39154, Stored XSS in CometChat JS SDK

Proof-of-concept for CVE-2024-4367 that generates a malicious PDF to exploit arbitrary JavaScript execution in PDF.js.

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Damn easy multiplatform Node.js RAT generator.

A standalone Blind XSS Script.

Generates initial access payloads abusing AddInProcess.exe via .NET deserialization, supporting HTA, VBA, JS, and CHM templates for in-memory code…

Haraj Script 3.7 - Authenticated Stored XSS

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

An interactive multi-user web JS shell

POC for PDF JS' CVE-2024-4367 vuln

Gitlab v12.4.0-8.1 RCE

CVE-2024-4367 arbitrary js execution in pdf js

Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS

"qs" prototype poisoning vulnerability ( CVE-2022-24999 )

CVE-2025-55182(React Server Components 反序列化远程代码执行漏洞)

Proof-of-concept exploit for CVE-2025-53964: remote file read/write via malicious XDXF dictionary in GoldenDict 1.5.0/1.5.1, leveraging unsanitized…

PoC Exploit CVE-2018-6389