
CVE-2026-71518
Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

Proof-of-concept exploit for CVE-2021-42013, demonstrating path traversal and remote code execution on Apache 2.4.50 via double URL encoding bypass…

Proof-of-concept for CVE-2021-43530, a Universal XSS vulnerability in Firefox for Android caused by improper URL sanitization when processing QR code…

Proof-of-concept exploit for CVE-2026-41940, an authentication bypass in cPanel & WHM, enabling unauthenticated access to the control panel.

A PoC for demonstrating CVE-2026-25604

react2shell PoC with Go / CVE-2025-55182

Analyzes CVE-2025-60423, an authentication bypass in JEECG versions 7.2.8 and 7.2.9, detailing path traversal and URL encoding techniques to bypass…

Python exploit script for CVE-2022-25581 (ClassCMS 2.4 arbitrary file download) that automates login, CSRF token extraction, malicious zip upload…

PoC exploit for CVE-2024-57241 targeting URL redirect vulnerability in DEDECMS 5.71SP1 and earlier. Includes a Python script with configurable target…

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

Unauthenticated SQL injection exploit for ABO.CMS 5.8 enabling login bypass and database takeover via the tb_login parameter.

Multi-threaded Python PoC scanner for CVE-2023-49103 that checks large URL lists for exposed phpinfo() output with .htaccess bypass via /.css path…

CVE-2023-40037: Incomplete Validation of JDBC and JNDI Connection URLs in Apache NiFi

Proof-of-concept demonstrating a URL parsing bypass in Python's urllib.parse (CVE-2023-24329) that allows bypassing blocklists by prepending spaces.

Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

Proof-of-concept exploit for CVE-2023-41080, demonstrating URL validation bypass in Apache Tomcat to redirect users to arbitrary external sites via…