
CVE-2026-39808
Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint

Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint

Remote Code Execution vulnerability on ArcSight Logger

XSS Vulnerability in Rittal

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

Proof-of-concept exploit for CVE-2019-9653 demonstrating unauthenticated remote code execution as root on NUUO NVR devices via vulnerable PHP scripts.

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

Artica Proxy before 4.30.000000 Community Edition allows SQL Injection.

Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

Artica Proxy before 4.30.000000 Community Edition allows Reflected Cross Site Scripting.

PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)

C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]

docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228

Proof-of-concept for stored and reflected XSS vulnerabilities in CheckMK Management Web Console versions 1.5.0 to 2.0.0p9, with detailed disclosure…

solution

CVE-2020-13159 - Artica Proxy before 4.30.000000 Community Edition allows OS command injection.

A PoC for CVE-2022-34169, for the SU_PWN challenge from SUCTF 2025