
CVE-2025-29927-PoC
Proof-of-concept exploit for CVE-2025-29927, a Next.js middleware authorization bypass. Includes a vulnerable target lab and Python script to verify…

Proof-of-concept exploit for CVE-2025-29927, a Next.js middleware authorization bypass. Includes a vulnerable target lab and Python script to verify…

A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)

Unauthenticated account takeover PoC for TranslatePress Multilingual <= 3.3.1 (WordPress)

SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

Stored XSS via Location Title in DPCalendar Free

Python proof-of-concept for testing SMTP command injection (CVE-2026-73570) by sending malformed RCPT TO addresses to detect shell command…

Expanded Exploit based on CVE-2024-41570

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

Proof-of-concept demonstrating CVE-2023-38831, a WinRAR path traversal vulnerability, by crafting a malicious ZIP archive that executes arbitrary…

Functional SQL injection exploit for CVE-2026-42167 in ProFTPD mod_sql, enabling unauthenticated attackers to inject commands via USER parameter.…

PoC, Dockerfile playground and root cause from patch diff analysis.

Proof-of-concept exploit for CVE-2021-21017, an Adobe Reader type confusion leading to out-of-bounds read and heap overflow, with technical analysis…

GNU telnetd service from GNU InetUtils authentication-bypass

Exploit For: CVE-2024-42845: Remote Code Execution (RCE) in Invesalius 3.1

Exploit For: CVE-2024-36840: SQL Injection Vulnerability in Boelter Blue System Management (Version 1.3)

CVE-2023-50164 (Apache Struts path traversal to RCE vulnerability) - Proof of Concept

Proof-of-concept exploit for CVE-2026-23744, a remote code execution vulnerability in MCPJam inspector <=1.4.2, triggered via crafted HTTP requests…