
CVE-2026-0920
Proof-of-concept exploit for CVE-2026-0920, an unauthenticated privilege escalation in LA-Studio Element Kit WordPress plugin, allowing creation of…

Proof-of-concept exploit for CVE-2026-0920, an unauthenticated privilege escalation in LA-Studio Element Kit WordPress plugin, allowing creation of…

Exploits CVE-2026-19598 in WordPress Pods plugin to create admin accounts or overwrite passwords via unauthenticated AJAX request, with mass scanning…

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)

Detailed penetration testing writeup for HackTheBox 'Connected' machine, covering exploitation of FreePBX CVE-2025-57819 (SQLi to RCE) and privilege…

This walkthrough documents the complete compromise of the HTB machine Connected.

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

Proof-of-concept exploit for CVE-2025-3248, a remote code execution vulnerability in Langflow, demonstrating exploitation of the vulnerable endpoint.

A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).

Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC

Proof-of-concept exploit for CVE-2026-22778, an unauthenticated RCE in vLLM's video processing, demonstrating heap address disclosure and a heap…

AJCloud AJY IPC Firmware Path Traversal via jdbhttpd

Proof-of-concept exploit for CVE-2026-34197, an RCE in Apache ActiveMQ via Jolokia's addNetworkConnector, with technical notes and reverse shell…

Proof-of-concept exploit for CVE-2026-19900, an authentication bypass and remote code execution vulnerability in LB-LINK X-PRO routers, allowing…

CVE-2020-1938 (Ghostcat) Tomcat AJP file read/file include PoC with python3 port

Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)

Proof-of-concept exploit for CVE-2026-0768 in Langflow, allowing remote command execution via crafted HTTP requests.

Python proof-of-concept for CVE-2022-25765, a command injection vulnerability in pdfkit, enabling remote code execution via crafted PDF generation.