


CVE-2025-41115

Exploit for CVE-2023-7028 - GitLab CE/EE

Broken Authentication in Wordpress plugin (Wawp Plugin < 3.0.18)

Exploit for CVE-2025-27580: A predictable token vulnerability in NIH BRICS through 14.0.0-67 allows unauthenticated users with a Common Access Card…


PoC for CVE-2022-48429 - Youtrack stored XSS

Oliver POS – A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation

Unauthenticated SQL injection exploit for CVE-2019-9053 in CMS Made Simple <= 2.2.9. Extracts admin creds with time-based SQLi.

https://medium.com/@mnqazi/cve-2023-4696-account-takeover-due-to-improper-handling-of-jwt-tokens-in-memos-v0-13-2-13104e1412f3

CVE-2025-29628, CVE-2025-29629, CVE-2025-29630, CVE-2025-29631

Token Login <= 1.0.3 - Authenticated (Subscriber+) Privilege Escalation

Cross-Site Request Forgery (CSRF) Vulnerability in HotelDruid 3.0.7 (CVE-2025-25748)

MLflow LFI/RFI Vulnerability -CVE-2023-1177 - Reproduced

Book Store Management System v1.0 - Incorrect Access Control

