
Public_Exploit-1--Wordpress-CVE-2021-29447
CVE-2021-29447 is an authenticated XML External Entity (XXE) vulnerability in WordPress

CVE-2021-29447 is an authenticated XML External Entity (XXE) vulnerability in WordPress

Python PoC exploit for CVE-2025-57231, an unauthenticated path traversal in Docmost < 0.22.0 that reads arbitrary files via the avatar endpoint.

Proof-of-concept and reproduction lab for CVE-2026-85706, an unauthenticated path-traversal file read in GitLab CE/EE repository commits and files…

Python PoC for CVE-2026-85706, an unauthenticated path traversal in GitLab CE/EE Repository Commits API that leaks arbitrary local files via a…

PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5).

This repository contains files for reproducing the vulnerability.

Discloses CVE-2023-51127, a directory traversal vulnerability in FLIR AX8 thermal cameras allowing unauthenticated remote attackers to read arbitrary…

Unauthenticated directory enumeration PoC for MRCMS V3.1.2, exploiting missing authentication in /admin/file/list.do to disclose server directory…

Demonstrates an improper access control vulnerability in DDSN Interactive cm3 Acora CMS 10.7.1, allowing editor-privileged users to retrieve…

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

Exploit script for CVE-2021-41277, an arbitrary file read vulnerability in Metabase, allowing unauthorized access to sensitive files.

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

A list of awesome penetration testing tools and resources.

These templates are suggestions of how the Obsidian notetaking tool can be used during an OSINT investigation. The example data in those files should…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Collects files and commands post-exploitation, formats them into Markdown reports, and helps find sensitive information for red team reporting.