
openfire-ssrf-cve-2019-18394
PoC for CVE-2019-18394: unauthenticated full-read SSRF in Openfire <= 4.4.2 FaviconServlet

PoC for CVE-2019-18394: unauthenticated full-read SSRF in Openfire <= 4.4.2 FaviconServlet

CTF lab and exploit toolkit for CVE-2026-29000, a pac4j-jwt JWE authentication bypass. Includes vulnerable Flask target, token forging library,…

Exploit for CVE-2025-59287, injecting WolfShell memory webshell into WSUS servers to achieve remote code execution when the admin console is opened.

halo cms plugin 1-request rce from a url, PoC + exploit chain

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

Exploit script for CVE-2024-50498 code injection in WordPress WP Query Console that checks vulnerability and delivers a reverse shell.

MAL-012: Reflected Cross-Site Scripting in Admin Console leading to Remote Code Execution in Payara Server

WSO2-2021-1258: Zip Slip vulnerability in WSO2 ESB

Craft CMS 3.0.25 - Cross-Site Scripting Vulnerability

CVE-2026-2586 — Eclipse GlassFish EL injection to RCE

CVE-2026-27174 - An unauthenticated remote code execution via the admin panel's PHP console feature

[CVE-2020-14882] Oracle WebLogic Server Authentication Bypass

This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading…

Proof of Concept and Security Advisory for XSS vulnerability in the FD602GW-DX-R410 fiber router’s admin console (firmware V2.2.14). Includes…

PoC (Proof of Concept) - CVE-2020-17453

Proof-of-concept for stored and reflected XSS vulnerabilities in CheckMK Management Web Console versions 1.5.0 to 2.0.0p9, with detailed disclosure…

Proof-of-concept for remote code execution in CheckMK Raw Edition 1.5.0–1.5.0p25 via misconfigured Dokuwiki embedded application allowing PHP code…

Proof-of-concept for a reflected XSS vulnerability in CheckMK Management Web Console (versions 1.5.0 to 1.6.0), enabling session theft or backdoor…