
CVE-2023-42222
Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

Sanitized report and loopback-only PoC script for CVE-2026-103584, a javascript: URL scheme XSS in MediaWiki CommonsMetadata LicenseUrl rendering.

Proof-of-concept exploit for CVE-2023-24329, a Python urllib parsing flaw enabling URL confusion attacks. Includes a runnable script and references…

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

Proof-of-concept for CVE-2024-27564, an unauthenticated SSRF in pictureproxy.php via the url parameter, with vulnerable code, curl PoC, and…

Stored XSS vulnerability proof-of-concept for Script Pag's 'Recent Ads' module, exploiting unsanitized double quotes in image URL fields to execute…

Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on…

Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)

Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor…

Documentation of CVE-2024-28515, a buffer overflow vulnerability in CSAPP Lab3 (buflab-update.pl), enabling remote code execution via crafted URL…

CVE-2023-49438 - Open Redirect Vulnerability in Flask-Security-Too

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

Vulnerability in D2L Brightspace's Learning Management System(LMS)

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2