
Wildfire
CVE-2026-39154, Stored XSS in CometChat JS SDK

CVE-2026-39154, Stored XSS in CometChat JS SDK
POC for PDF JS' CVE-2024-4367 vuln

JS Job Manager < 1.1.9 - Unauthenticated Arbitrary Plugin Installation/Activation

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

PoC Exploit CVE-2018-6389

Regular expression matching for URL's. Maintained, safe, and browser-friendly version of url-regex. Resolves CVE-2020-7661 for Node.js servers.

Chrome V8 RCE exploit for CVE-2021-30632 targeting Windows systems. Tested on Chrome 91-93. Includes JS POC and in-the-wild bug analysis reference.

PoC of CVE-2024-33883, RCE vulnerability of ejs.

IMPORTANTE: Proyecto de Next JS VULNERABLE creado solo para fines educativos, de pruebas y explotación, NO SE RECOMIENDA INSTALACIÓN EN PRODUCCION,…

Proof-of-concept exploit for CVE-2025-53964: remote file read/write via malicious XDXF dictionary in GoldenDict 1.5.0/1.5.1, leveraging unsanitized…

WordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerability

CVE-2024-4367 arbitrary js execution in pdf js

Detailed analysis of CVE-2024-28397, a sandbox escape vulnerability in js2py enabling RCE via Python object traversal. Includes code analysis, PoC,…

PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk…

PoC for Arbitrary Code Execution in Notable

CVE-2022-23861: Multiple Stored Cross-Site Scripting in YSoft SafeQ

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS