
CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below
Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

Exploit for CVE-2021-43857 in Gerapy v0.9.7, providing a reverse shell via authenticated project creation and command injection.

PoC for CVE-2025-13342

Proof-of-concept checker for CVE-2025-11833, allowing security researchers to test vulnerable web applications with configurable credentials and loot…

CVE-2025-10377

PoC for CVE-2025-65271 | Found by me

Proof-of-concept exploit for CVE-2024-21683, a remote code execution vulnerability in Atlassian Confluence. Executes a JavaScript payload against…

CVE-2023-43148

XSS in Simple Cashiering System

All details about CVE-2022-43097

CVE-2025-41646 - Critical Authentication bypass

Based on the x.pl exploit/loader script for CVE-2009-1151

PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation

Unauthenticated Privilege Escalation to Administrator via Role Form Field

CVE-2025-15495 - Arbitrary File Upload Leading to Remote Code Execution (RCE)

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass

Pluck v4.7.18 - Remote Code Execution (RCE)

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload