
cve-2021-33879
GameLoop update MITM

GameLoop update MITM
Automatic SSTI detection tool with interactive interface

Apache Tomcat source code repository for CVE-2012-4431, a Java servlet container vulnerability. Provides the vulnerable codebase for analysis and…

ZenoMinder Blind SQL Injection PoC

Altenergy Power System Control Software set_timezone RCE Vulnerability (CVE-2023-28343)


Authenticated remote code execution exploit for eXtplorer 2.1.15 on Joomla. Python-based tool targeting insecure permissions to gain shell access.

Proof-of-concept SQL injection exploit for FUXA SCADA software (<=1.1.12) via HTTP POST JSON id parameter, enabling extraction of SQLite database…

CVE-2022-48474 &CVE-2022-48475 PoCs & exploits

Proof-of-concept exploit for CVE-2017-7358, demonstrating a specific vulnerability in a software application. Intended for security research and…

Proof-of-concept for a reflected XSS vulnerability in CheckMK Management Web Console (versions 1.5.0 to 1.6.0), enabling session theft or backdoor…

Unauthenticated SQL injection exploit for GLPI versions before 10.0.18, enabling database enumeration, credential extraction, and API token…

Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819

Proof-of-concept for CVE-2026-33017, demonstrating unauthenticated remote code execution in vulnerable Langflow versions through malicious…

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password…

Proof-of-concept exploit for CVE-2026-25939, an unauthenticated authorization bypass in FUXA SCADA software allowing arbitrary scheduler manipulation…

Cisco ASA Software and ASDM Security Research

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…