
CVE-2026-14894
Super Forms Unauthenticated File Upload RCE | CVSS 9.8

Super Forms Unauthenticated File Upload RCE | CVSS 9.8

CVE-2025-55182 — Unauthenticated RCE in React Server Components (React2Shell). CVSS 10.0 exploit tool for authorized penetration testing.

MISP <= 2.5.27 - Stored Cross-Site Scripting via Workflow Engine (doT.js Template Injection).

📂 Grafana LFI Exploit (CVE-2021-43798). Extracción automatizada de credenciales y configuración. 🕵️

CVE-2023-4220 — Unauthenticated file upload RCE in Chamilo LMS ≤ 1.11.24. OSCP-style and auto exploit.

Proof-of-concept exploit for CVE-2025-29927, demonstrating Next.js middleware bypass via the x-middleware-subrequest header to circumvent…

FreePBX CVE-2025-57819 lab (Docker) + Nuclei POC for unauth SQLi (time-based).

CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner…

Python exploit for CVE-2025-13486 targeting unauthenticated remote code execution and privilege escalation in the ACF Extended WordPress plugin, with…

Proof-of-concept exploit for CVE-2017-5487 enabling WordPress user enumeration via REST API, with WAF bypass techniques. PowerShell-based tool for…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

🔱 Powerfull XSS Scanning and Parameter analysis tool&gem

Real-time data leak monitoring and OSINT tool that checks credentials against multiple breach databases, scans CVEs, Google Dorks, and Pastebin, with…