
CVE-2025-13407
GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

Research artifact repository containing fuzzing corpora (liblnk, tcpdump, vim), a Telegram privacy vulnerability report, and supporting scripts for…

Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

Detailed analysis and PoC for CVE-2025-67887/86 RCE in 1C-Bitrix Translate module, including exploit chain, CVSS scoring, and mitigation…

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

CVE-2017-7679 POC SCRIPT BY LORDWARE....

Automated vulnerability scanner for CVE-2023-28121 that checks a list of targets concurrently and delivers results via Telegram notifications.

Exploit for CVE-2025-32429 – SQLi in XWiki REST API (getdeleteddocuments.vm).

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

Proof-of-concept exploit for a buffer overflow vulnerability in Tenda routers. Sends crafted unauthenticated POST requests to trigger a crash and…

PoC Exploit for CVE-2025-7753 — Time-Based SQL Injection in Online Appointment Booking System 1.0 via the username parameter. Exploit written in C…

Frida-based proof-of-concept demonstrating authentication bypass in Telegram Android by hooking SharedConfig.checkPasscode to always return true,…

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

Proof-of-concept exploit for CVE-2023-3047 SQL injection vulnerability in TMT Lockcell. Demonstrates manual exploitation using cURL and Burp Suite to…

Vthunting is a tiny script used to generate report about Virus Total hunting and send it by email, slack or telegram.

Exploit Win10Pcap Driver to enable some Privilege in our process token ( local Privilege escalation )