
CVE-2025-14783-POC
🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

Comprehensive analysis and proof-of-concept for CVE-2025-6218 - WinRAR path traversal RCE vulnerability affecting versions 7.11 and earlier

Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting

This repository documents CVE-2026-48849, a Stored Cross-Site Scripting (XSS), HTML Injection, and CSS Injection vulnerability discovered in…

A PoC exploit for CVE-2021-22873 - Revive Adserver Open Redirect Vulnerability.

Proof of concept for CVE-2020-7247 for educational purposes.

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

Curated list of CVE-2020-0601 resources

CVE-2025-52204: Reflected XSS / HTML Injection in Znuny OTRS

If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on…

CVE-2026-24415 - OpenSTAManager Affected by XSS in modifica_iva.php via righe parameter

LetsDefend SOC336 case study on CVE-2025-21298

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

Winrar Exploit CVE-2023-38831

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…

A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the eScan Management Console (version 14.0.1400.2281) developed by Microworld…