
CVE-2025-44137
Proof-of-concept exploit for CVE-2025-44137: unauthenticated directory traversal in MapTiler Tileserver-php v2.0, enabling arbitrary file read via…

Proof-of-concept exploit for CVE-2025-44137: unauthenticated directory traversal in MapTiler Tileserver-php v2.0, enabling arbitrary file read via…

Proof-of-concept exploit for unauthenticated reflected XSS in MapTiler Tileserver-php v2.0 via the 'layer' GET parameter, enabling arbitrary HTML/JS…

Proof-of-concept exploit for CVE-2026-37070: an authenticated attacker can read arbitrary uploaded files in Veno File Manager 4.4.9 via a crafted GET…

Proof-of-concept exploit for CVE-2025-60574, a Local File Inclusion vulnerability in tQuadra CMS 4.2.1117, enabling arbitrary file retrieval via…

Proof-of-concept exploit for command injection vulnerability in Aztech WMB250AC routers, enabling authenticated privilege escalation to root shell…

Exploit for CVE-2024-57784: authenticated directory traversal in Zenitel AlphaWeb XE 11.2.3.10. Enables remote file reading via HTTP GET requests…

Proof-of-concept exploit for CVE-2018-6574, demonstrating arbitrary command execution via crafted import paths in Go's go get command.

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

Python test client that sends HTTP GET requests with oversized Authorization headers to trigger header-parsing bugs like CVE-2025-4476. For…

CLI tool for open source and threat intelligence

Exploit and detect tools for CVE-2020-0688


Tools for investigating Log4j CVE-2021-44228

Exploits CVE-2021-40444 in Microsoft Office Word to achieve remote code execution through the MSHTML engine by injecting malicious content into a…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.

Proof-of-concept exploit for CVE-2017-8295, a WordPress password reset vulnerability allowing attackers to obtain reset links without authentication,…