
CVE-2025-25615
Proof-of-concept demonstrating incorrect access control in Unifiedtransform v2.0, allowing teachers to view attendance for any class section via…

Proof-of-concept demonstrating incorrect access control in Unifiedtransform v2.0, allowing teachers to view attendance for any class section via…

Proof-of-concept exploit for SQL injection in Sourcecodester Cab Management System 1.0, demonstrating arbitrary SQL execution via the id parameter in…

Proof-of-concept for CVE-2025-65094: privilege escalation via IDOR in WBCE CMS. Demonstrates group ID manipulation to gain admin access, with…

Proof-of-concept for CVE-2025-66204: brute-force protection bypass in WBCE CMS via spoofed X-Forwarded-For header, with automated Python exploit…

Proof-of-concept for CVE-2021-3395: authenticated stored XSS in Pryaniki 6.44.3 via arbitrary file upload, triggering JavaScript on attachment view.

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

Research on GraphQL from an AppSec point of view.

Stored XSS via User-Agent in Admin Order View in PhocaCart

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

CVE-2021-21978 exp

CVE-2019-5418 - File Content Disclosure on Ruby on Rails

This Tool To Test Machine Keys In View State

CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0…

Proof-of-concept for CVE-2025-66024: Stored XSS in XWiki Blog Application via unescaped post title in HTML title tag. Includes reproduction steps,…

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

Exploit PoC for CVE-2025-53770 enabling webshell upload to SharePoint, ValidationKey extraction, signed ViewState generation, and remote code…

CVE-2026-24417 - OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service

CVE-2026-22243 - EGroupware has SQL Injection in Nextmatch Filter Processing