
CVE-2025-29557
Documents a high-severity ExaGrid EX10 MailConfiguration API access control flaw that leaks plaintext SMTP credentials to authenticated operators,…

Documents a high-severity ExaGrid EX10 MailConfiguration API access control flaw that leaks plaintext SMTP credentials to authenticated operators,…

Educational demo of CVE-2025-4664, a Chrome Loader vulnerability enabling cross-origin data leakage via referrer-policy manipulation. Includes a…

Technical analysis and proof-of-concept for CVE-2024-6387, a race condition in OpenSSH signal handling enabling unauthenticated remote code execution…

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI)

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users…

simple program for joomla scanner CVE-2023-23752 with target list

PoC and exploit for Apache HTTP Server 2.4.49 path traversal vulnerability (CVE-2021-41773) with Docker setup, curl-based exploitation commands, and…

CVE-2025-50777: Root Access and Plaintext Credential Exposure in AZIOT Smart CCTV

A repository used for Hackthebox ServMon Machine

The Eventin plugin (<= 4.0.26) for WordPress contains an unauthenticated arbitrary file read vulnerability

HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)

Python exploit script for CVE-2021-39174 Cachet information disclosure and remote code execution via Twig Server-Side Template Injection, with…

Proof-of-concept exploit for Jenkins arbitrary file leak vulnerability (CVE-2024-23897). Enables unauthorized file disclosure for security testing…

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in FlatPress CMS 1.3.1, demonstrating payload injection and impact including…

CVE-2017-7529- Check and EXPLOIT

Proof-of-concept exploit for CVE-2023-23752 targeting unauthenticated information disclosure in Joomla! versions 4.0.0 to 4.2.7. Includes a Python…

CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8

Vite WASM Import Path Traversal 🛡️