
CVE-2025-10035
A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to…

This repository contains a safe Proof of Concept (PoC) to detect vulnerable SmarterMail versions affected by CVE‑2025‑52691. The script performs…

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

Cisco Adaptive Security Appliance Software/Cisco Firepower Threat Defense - Directory Traversal

Python exploit class for CVE-2025-58360, an XXE vulnerability in GeoServer's GetMap function enabling arbitrary file read. Includes automated…

Analysis and remediation guide for CVE-2025-14847 (MongoBleed), a MongoDB zlib compression memory disclosure. Includes detection indicators,…

An authenticated Directory Traversal vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file manager…

A small Rust CLI that reproduces the information-disclosure pattern associated with CVE-2015-6668 (Job Manager <= 0.7.25).

Proof-of-Concept (PoC) for CVE-2025-62168 👾

An issue was discoverd in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive…


Public advisory for CVE-2025-50341 in Axelor

An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout…

A security vulnerability scanner for detecting the React2Shell vulnerability (CVE-2025-55182) in Next.js and React applications.

Proof-of-concept exploit for CVE-2023-31059, an unauthenticated path traversal in Repetier-Server ≤1.4.10, enabling arbitrary file read via crafted…

Disclosure for CVE-2025-8091

This is a fast, asynchronous Python tool that fingerprints domains for likely Next.js App Router / React Server Components (RSC) infrastructure. (I…

Proof-of-concept exploit for CVE-2025-52399, demonstrating SQL injection in the Institute-of-Current-Students application via the loginlinkfaculty…