
CVE-2025-13407
GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload
Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

Research artifact repository containing fuzzing corpora (liblnk, tcpdump, vim), a Telegram privacy vulnerability report, and supporting scripts for…

Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

CVE-2017-7679 POC SCRIPT BY LORDWARE....

Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

Proof-of-Concept exploit for CVE-2025-7795 – A buffer overflow vulnerability affecting certain Tenda routers. The exploit sends crafted POST requests…

PoC Exploit for CVE-2025-7753 — Time-Based SQL Injection in Online Appointment Booking System 1.0 via the username parameter. Exploit written in C…

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass


Vthunting is a tiny script used to generate report about Virus Total hunting and send it by email, slack or telegram.

Exploit Win10Pcap Driver to enable some Privilege in our process token ( local Privilege escalation )