
CVE-2026-29053
Python PoC and version scanner for CVE-2026-29053, an authenticated RCE in Ghost CMS below 6.19.1 via malicious Handlebars theme templates.

Python PoC and version scanner for CVE-2026-29053, an authenticated RCE in Ghost CMS below 6.19.1 via malicious Handlebars theme templates.

Proof-of-concept exploit for CVE-2023-4762, a Chromium V8 type confusion vulnerability enabling remote code execution via crafted JavaScript.

Exploit chain for Flowise 3.0.5: unauthenticated account takeover via password-reset token disclosure (CVE-2025-58434) chained to CustomMCP…

Reflected XSS vulnerability disclosure for ZenShare Suite login_newpwd.php, allowing arbitrary JavaScript execution via crafted URL in codice_azienda…

Proof-of-concept exploit for CVE-2026-27574, a critical code injection in OneUptime enabling remote code execution and environment variable leakage.

Exploit for CVE-2024-21683, a post-authentication remote code execution vulnerability in Atlassian Confluence Server and Data Center, allowing…

Generates and delivers exploit payloads for CVE-2026-23830, a SandboxJS escape, with modes for blind OOB exfiltration and local calc PoC. Supports…

Exploit for Apache Solr CVE-2026-22444, leveraging UNC path injection and SMB server to achieve remote code execution via malicious configset and…

CVE-2026-39154, Stored XSS in CometChat JS SDK

CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini…

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

A standalone Blind XSS Script.

Post-auth RCE exploit for ArcadeDB via JavaScript trigger GraalVM sandbox escape, executing OS commands over HTTP API with reverse shell or blind…

Node.js reverse shell payload generator for penetration testing. Creates bind and reverse shells in JavaScript.

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

Proof-of-concept exploit for a stored XSS vulnerability in TinyFileManager v2.4.7, enabling arbitrary JavaScript execution and session cookie…

Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript…