
CVE-2026-4802
Proof-of-concept exploit for CVE-2026-4802, a command injection vulnerability in Cockpit's system logs UI, enabling arbitrary command execution and…

Proof-of-concept exploit for CVE-2026-4802, a command injection vulnerability in Cockpit's system logs UI, enabling arbitrary command execution and…

Metabase CVE-2026-59827 Vulnerability Scanner

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

Proof-of-concept exploit for FortiOS authentication bypass (CVE-2024-55591) that allows unauthenticated access to system logs via WebSocket on…

CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

Proof-of-concept CSRF exploit for One Identity Cloud Access Manager 8.1.3 that logs out victims via a crafted HTML form submission.

Stored XSS in TastyIgniter v3.0.7 Restaurtant CMS

Test exploit of CVE-2021-44228

Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal +…

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

Proof-of-concept exploit for CVE-2025-31324, a remote code execution vulnerability in SAP NetWeaver, with Shodan dorks for target discovery and…

CVE-2025-10377

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

Proof-of-concept exploit for CVE-2023-32315, a path traversal vulnerability in Openfire's setup/log.jsp, enabling unauthenticated access to sensitive…

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

Unauthenticated arbitrary file upload exploit for WooCommerce Return Refund and Exchange plugin (CVE-2022-4047). Scans targets, uploads webshell, and…

Simple webapp that is vulnerable to Log4Shell (CVE-2021-44228)

Quick test environment for CVE-2021-44228 Log4j RCE vulnerability with a built-in exploit server and customizable payload execution.