
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

CVE Reproduction: cve-2024-43451-ntlm_hash_disclosure_reproduction

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

Proof-of-concept exploit generator for reflected XSS in STIG Manager OIDC authentication, enabling session token theft via crafted callback URLs and…

Documentation and proof-of-concept for CVE-2026-30502, a reflected XSS vulnerability in OpenKM v6.3.12. Includes technical analysis, root cause,…

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

Educational guide on CVE-2024-21413, the Outlook zero-click Moniker Link vulnerability, covering attack flow, NTLM credential capture, detection with…

Chamilo-LMS (v2.0) CVE-2025-26153

Comprehensive analysis and proof-of-concept for CVE-2025-6218 - WinRAR path traversal RCE vulnerability affecting versions 7.11 and earlier

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure


This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln

Proof-of-concept for a Self-XSS vulnerability in ChatGPTUtil, demonstrating cookie theft and account hijacking via crafted SVG payloads pasted into…

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

CVE-2024-42009 Proof of Concept

Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation,…

Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload