
CVE-2025-2539
Proof-of-concept exploit for CVE-2025-2539 targeting WordPress File Away plugin. Exploits missing capability check and weak algorithm to read…

Proof-of-concept exploit for CVE-2025-2539 targeting WordPress File Away plugin. Exploits missing capability check and weak algorithm to read…

Exploit CVE-2025-24071

PoC for CVE-2021-29447

Advisory and technical analysis of CVE-2025-5777 (CitrixBleed 2), a critical memory disclosure in Citrix NetScaler ADC and Gateway, covering root…

PoC de CVE-2026-20224: inyeccion XXE para lectura de archivos en Cisco Catalyst SD-WAN Manager (no autenticado).

The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to…

Vulnerability Case Study: CVE-2026-33829 (Windows Snipping Tool NTLM Coercion)

Hack The Box - Silentium machine writeup | CVE-2025-58434, CVE-2025-59528, CVE-2025-8110

CVE-2015-6668, relacionada con el plugin WP Job Manager para WordPress (versiones ≤ 0.7.25).

Python-based scanner for CVE-2024-27954, a Local File Inclusion vulnerability in the WordPress wp-automatic plugin. Supports multithreaded scanning,…

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

Write-up of CVE-2022-22828

Artica Proxy before 4.30.000000 Community Edition allows Reflected Cross Site Scripting.

Python exploit for CVE-2025-4380, a Local File Inclusion vulnerability in the Ads Pro WordPress plugin. Supports single and mass target scanning with…

Vite Development Server's @fs endpoint (CVE-2025-31125) to access sensitive files like /etc/passwd and /etc/hosts via crafted URLs.

Docker-based reproduction environment for CVE-2017-7529 Nginx integer overflow vulnerability, demonstrating information disclosure via crafted Range…

Small Powershell Script to detect Running Printer Spoolers on Domain Controller