
Blackash-CVE-2025-31161
CVE-2025-31161

CVE-2025-31161

Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

Proof-of-concept exploit for CVE-2023-24249, an arbitrary file upload vulnerability in laravel-admin, enabling web shell deployment for penetration…


Updated exploit for CVE-2021-22911 (Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated))

Wordpress Video Gallery - YouTube Gallery and Vimeo Gallery Plugin SQL Injection

GitHub repository for CVE-2023-3460 POC

Authenticated reflected XSS in TastyIgniter version v3.2.2.

Demonstrates the x-middleware-subrequest header bypass in Next.js 13.4.19, allowing unauthorized access to protected routes. Includes setup, normal…

Zoo Management System 1.0 - Stored Cross-Site-Scripting (XSS)

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE


CVE-2021-42562: Improper Access Control in MITRE Caldera

Proof-of-concept exploit for CVE-2024-53617: stored XSS in LibrePhotos enabling account takeover via malicious HTML file upload with IDOR bypass.

TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

TP-Link Archer BE800 V1 — VPN Key Injection RCE

CVE-2021-26855: PoC (Not a HoneyPoC for once!)