
CVE-2020-13259
PoC of Full Account Takeover on RAD SecFlow-1v

PoC of Full Account Takeover on RAD SecFlow-1v

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

TCP Port Forwarding Utility on C

CVE-2023-7028

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected…

CVE-2025-59501 POC code

Improper Access Control in Mysterium Node before v1.36.0


PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)

A drone engineered to autonomously seek out, hack, and wirelessly take full control over any other Parrot or 3DR drones within wireless or flying…

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

Technical Reference to multiple relay techniques

This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).