
packetfence-CVE-2024-39024
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution

Unverified Password Change (CWE-620)

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…

Authenticated SQL injection to command execution on Cacti 1.2.12

Web CTF challenge highlighting moodle CVE-2025-26529 (in 2 flavors)

Go-based exploit tool for CVE-2022-40684 (Fortinet authentication bypass). Automates SSH key injection for authorized penetration testing and…

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM (HTML Injection)

CVE-2024-46879 - Tiki CMS Reflected Cross-Site Scripting (XSS) Vulnerability

WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution

Docker-based lab for CVE-2024-27198 TeamCity authentication bypass. Includes exploit reproduction, IoC hunting with Sigma/Suricata rules, and…

FOGProject Authentication bypass CVE-2025-58443 Exploit

CVE-2022-3552 RCE with detailed exploitation steps

An improved POC exploit based on the reported CVE on exploitdb

Metasploit exploit for the CVE-2025-50286.

The code for personally reproducing the corresponding vulnerability

CVE-2022-43110

Python POC, Exploit for CVE-2026-29000

Lab for the CVE-2024-27198