
CVE-2026-19478-PoC
Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Python exploit for CVE-2017-7921 in Hikvision IP cameras, performing unauthenticated user enumeration, snapshot capture, and configuration file…

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

This Repositories contains list of One Liners with Descriptions and Installation requirements

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

Passive security checker for CVE-2026-48908 affecting SP Page Builder.


Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

Validates pre-authentication reflected XSS in WordPress, fingerprints vulnerable versions, checks payload reflection and JSONP, and generates…

This is a pre-authenticated RCE exploit for VMware vRealize Operations Manager

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC