
CVE-2026-5027
Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…

Proof-of-concept exploit for unauthenticated remote code execution in MaxSite CMS <= 109.1 via MarkItUp editor AJAX endpoints, with detection and…

Detailed technical write-up and proof-of-concept for CVE-2026-25548, a critical RCE in InvoicePlane 1.7.0 via LFI and log poisoning, including attack…

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

Exploit for CVE-2025-10352. Admin account creation on Melis Platform Framework

Exploit for CVE-2026-3844, an unauthenticated arbitrary file upload leading to RCE in Breeze Cache WordPress plugin. Includes lab setup, usage, and…

Centreon exploits CVE-2026-2749, CVE-2026-2751 and CVE-2026-2750

Proof-of-concept exploit for pre-authenticated remote code execution in Marimo via the WebSocket endpoint, allowing unauthenticated attackers to…

GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.

Python PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (default port 6274)

Scanner and educational guide for CVE-2025-49844 (RediShell), a Redis Lua scripting use-after-free vulnerability. Checks Redis servers for exposure,…

Proof-of-concept exploit for CVE-2026-24126, an arbitrary file read in Weblate via SSH host argument injection, allowing authenticated admins to read…

Proof-of-concept exploit for CVE-2026-1560, an authenticated remote code execution vulnerability in Lazy Blocks WordPress plugin, allowing…

Proof-of-concept exploit for CVE-2023-22527, a server-side template injection in Confluence that enables remote code execution. Includes a Python…

Local privilege escalation exploit for CVE-2026-3888 targeting snap-confine and systemd-tmpfiles on Ubuntu, providing SUID and capabilities variants…

Docker Compose setup to demonstrate the nginx-ui missing authentication vulnerability

Proof-of-concept exploit for CVE-2023-7028, automating GitLab account takeover via password reset email manipulation. Includes temp-mail integration…

Proof-of-concept exploit for CVE-2026-31908, a critical header injection vulnerability in Apache APISIX, demonstrating authentication bypass and…