
metasploit-framework
Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…


PoC for CVE-2025-64512: pdfminer.six CMapDB pickle deserialization RCE via crafted PDF

CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip


Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code…

Store vulnerability POC files including CVE-2026-42588 Spring RCE xml payload

Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

CVE-2023-50164 PoC Application & Exploit script

Validates pre-authentication reflected XSS in WordPress, fingerprints vulnerable versions, checks payload reflection and JSONP, and generates…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Proof of concept for CVE-2026-18649, a remote denial of service vulnerability in GStreamer's H.264 RTP depayloader (rtph264depay).

CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated,…