
CVE-2009-0182
CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

Step-by-step reproduction environment for CVE-2018-6905, a stored XSS vulnerability in TYPO3 install.php, with Docker setup and payload execution…

Python-based proof-of-concept for CVE-2022-22965 (Spring4Shell) that writes a marker file to the Tomcat webapps directory and validates exploitation…

Proof-of-concept exploit for CVE-2025-24071 that creates a .searchconnector-ms file to trigger SMB authentication when copied, enabling credential…

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

PunkBuster LPI to NT AUTHORITY\SYSTEM

automated SQL injection for QCubed profile.php file

Pre-authentication remote code execution exploit targeting GitLab CE/EE via ExifTool DjVu parsing. Uploads a crafted image to trigger RCE on…

Proof-of-concept exploit for CVE-2024-29272, an unauthenticated arbitrary file upload vulnerability in VvvebJS < 1.7.5, enabling remote code…

CVE-2023-24055 PoC (KeePass 2.5x)

POC of DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

Proof-of-concept exploit for CVE-2025-66676 demonstrating arbitrary process termination via IOBit Unlocker kernel driver, with checksum bypass…

Proof-of-concept for CVE-2023-50164 (Apache Struts 2), originally by jakabakos and adapted for the HTB Strutted lab environment. For educational use…

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…