
CVE-2026-19501-poc
Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

🐾Dogwalk PoC (using diagcab file to obtain RCE on windows)


Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.10.1321 - Cross-Site Request Forgery to…

OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious php codes.


Unauthenticated Xerte Online Toolkits exploit. Requires knowing a valid username.

Another spring4shell (Spring core RCE) POC

A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.

WonderCMS Authenticated RCE - CVE-2023-41425

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)


Multiple Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the…

CVE-2021-44228 (Log4Shell) Proof of Concept

CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a…

CVE-2021-46079 - An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can…

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

This repository contains a Proof of Concept (PoC) exploit for the **CVE-2025-47175** vulnerability found in Microsoft PowerPoint. The vulnerability…