
CVE-2025-12139-WordPress-Integrate-Google-Drive-Exploit
Golang PoC exploit for CVE-2025-12139 targeting the Integrate Google Drive WordPress plugin. Extracts sensitive OAuth credentials (Client ID, Secret,…

Golang PoC exploit for CVE-2025-12139 targeting the Integrate Google Drive WordPress plugin. Extracts sensitive OAuth credentials (Client ID, Secret,…

Automated exploit for CVE-2026-27944 in Nginx UI: downloads and decrypts backups, extracts secrets, and creates rogue admin accounts for full…

Exploit for CVE-2018-20555: automated discovery and takeover of Twitter accounts via leaked API keys in vulnerable Social Network Tabs WordPress…

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected…

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

Takeover of Oracle WebLogic Server

Proof-of-concept demonstrating unauthenticated cross-origin takeover of Nhost MCP Server, enabling database exfiltration, table drops, and permission…

Proof-of-concept exploit for CVE-2021-35587, an unauthenticated remote code execution vulnerability in Oracle Access Manager, allowing full takeover…

Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.

PoC exploit for VMware Cloud Director RCE (CVE-2020-3956)

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account…

CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection

PoC of Full Account Takeover on RAD SecFlow-1v

Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.

Proof-of-concept exploit for CVE-2021-24085: CSRF-based elevation of privilege in Microsoft Exchange Server via msExchEcpCanary token forgery,…

Proof-of-concept demonstrating stored XSS in Appsmith Table Widget leading to vertical privilege escalation and full admin takeover via XSS-to-CSRF…

A CSRF POC for Updating the Profile of a Hospital leading to Account Takeover