
CVE-2023-5965
PoC for Espo CRM 7.2.4 CVE-2023-5965 & CVE-2023-5966

PoC for Espo CRM 7.2.4 CVE-2023-5965 & CVE-2023-5966
Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

In OctoPrint version <=1.11.2, an attacker with file upload access (e.g., valid API key or session) can craft a malicious filename that bypasses…

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…

The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

patched to work

Proof of Concept of an unsafe pickle deserialization vulnerability in Socket.IO

File upload vulnerability in machsol machpanel 8 allows attacker gain a webshell.

Covert C2 framework using QR codes for indirect command execution and result retrieval via HTTP/S, designed for stealthy penetration testing and red…

Embed a reverse shell in Notion pages using the Notion API as a proxy, enabling stealthy remote shell sessions with encrypted and authenticated…


Remote Windows keylogger with AES-256 encrypted keystroke exfiltration via configurable callback intervals and a companion Python server for log…

CVE-2023-30459

A PoC for CVE-2025-24813

CVE-2024-39069
