
CVE-2026-77276-PoC
CVE-2026-77276 pre-auth macro RCE via convert-to on Collabora Online

CVE-2026-77276 pre-auth macro RCE via convert-to on Collabora Online
Exploit For SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)

WordPress Online Booking & Scheduling Calendar for WordPress by vcita Plugin <= 4.5.3 is vulnerable to a medium priority Arbitrary File Upload

Proof-of-concept for stored XSS in Online Car Rental System 1.0, demonstrating session hijacking and credential theft via the vehicalorcview…

Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…

Proof-of-concept exploit for SQL injection in CodeAstro Online Job Portal allowing authenticated deletion of all job records via crafted GET request.

Proof-of-concept demonstrating an IDOR vulnerability in CodeAstro Online Job Portal allowing authenticated employers to delete arbitrary job postings…

code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

Learning Exploit Development for Web. POCs for CVEs which was assigned to me.

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

Unauthenticated Xerte Online Toolkits exploit. Requires knowing a valid username.

Proof-of-concept exploit for SQL injection in Sourcecodester Online Pizza Ordering System 1.0. Demonstrates remote code execution and denial of…

This is a EXP For CVE-2025-57576. PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site > Scripting (XSS) in /admin/updateorder.php


Potential malicious code execution via CHM hijacking (CVE-2019-9896)


PoC, Hunting React2Shell about CVE-2025-55182