
CVE-2024-4367-Analysis
Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js

Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js

Proof-of-concept exploit for a V8 JavaScript engine vulnerability (CVE-2025-6554) demonstrating a TDZ bypass that leaks 'The Hole' sentinel, enabling…

Proof-of-concept exploit and technical write-up for CVE-2026-73319, a same-host javascript: URI XSS in XenForo before 2.3.13, including reproduction…

Proof-of-concept exploit for CVE-2025-6554, a V8 JavaScript engine vulnerability allowing unauthorized access to uninitialized 'Hole' values via…

PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).

Technical analysis of Adobe Acrobat JavaScript trust boundary flaw, documenting native handler mappings and privilege-gating logic for CVE-2026-34621.


Proof-of-concept exploit and writeup for CVE-2022-44789, a heap buffer overflow in MuJS JavaScript interpreter, including vulnerable version and…

Research PoC demonstrating a prototype pollution and JavaScript injection chain in Adobe Acrobat Reader, enabling privileged JavaScript execution and…

Stored XSS vulnerability proof-of-concept for Script Pag's 'Recent Ads' module, exploiting unsanitized double quotes in image URL fields to execute…

Technical disclosure for CVE-2024-28784 — a stored XSS vulnerability in IBM QRadar SIEM 7.5.0 UpdatePackage 7. The issue affects the Rule Wizard…

JavaScript-based exploit for Adobe Reader CVE-2014-0521 with proof-of-concept PDFs demonstrating file reading and data exfiltration via WebDAV.

A PoC for demonstrating CVE-2026-26903

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

Reproduction of a WebAssembly use-after-free vulnerability in Mozilla's JavaScript engine, demonstrating a deterministic race condition and providing…

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

A JavaScript Obfuscator based on Cryptographic Indistinguishability Obfuscation techniques

Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on…