
CVE-2026-44401
Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

An information gathering tool to collect git commit emails in version control host services

CVE-2013-2028 python exploit

Put the *.py files to test/functional folder of bitcoin sourcecode (commit: 4901c00792c1dabae4bb01e6373c9b1ed9ef3008)

PoC for CVE-2022-23614 (Twig sort filter code execution/sandbox bypass)

Proof of concept for CVE-2022-36234



CVE-2026-54597 - Authenticated Time-Based Blind SQL Injection in ITFlow

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

CVE-2026-54596 - Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration





PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…