
Hvv2023
HW2023@POC@EXP@CVE-2023-2023

HW2023@POC@EXP@CVE-2023-2023

WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering

CVE-2019-12836

Validates pre-authentication reflected XSS in WordPress, fingerprints vulnerable versions, checks payload reflection and JSONP, and generates…

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…

Generates detection artifacts for CVE-2026-21902 on Juniper Junos Evolved, enabling verification of unauthenticated remote code execution via command…

Aimy Captcha-Less Form Guard Joomla Component PHP Object Injection RCE. clfgd XOR keystream recovery + unserialize(). CVSS 10.0 | CWE-502 |…

Exploit CVE-2020-29134 - TOTVS Fluig Platform - Path Traversal

Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.

XSS-to-RCE exploit for Wonder CMS 3.2.0–3.4.2 with automated payload delivery, reverse shell, and cookie theft via malicious theme installation.

Use java.net.InetAddress for detection

Python exploit script for CVE-2025-31161 targeting CrushFTP. Enumerates users and creates malicious accounts with elevated permissions via HTTP…

Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)

Updated python3 exploit for CVE-2018-10583 (LibreOffice/Open Office - '.odt' Information Disclosure )

Unauthorized Arbitrary File Download in WordPress WP01

Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection…