
CVE-2026-15667
Python proof-of-concept for CVE-2026-15667, an authenticated local file inclusion in the WordPress Eventin plugin via the event_layout REST field.

Python proof-of-concept for CVE-2026-15667, an authenticated local file inclusion in the WordPress Eventin plugin via the event_layout REST field.

Exploit for CVE-2023-39361 in Cacti, a network graphing solution, demonstrating SQL injection vulnerability for educational and security testing…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

A PoC for CVE-2022-34169, for the SU_PWN challenge from SUCTF 2025

Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

Proof-of-concept for stored and reflected XSS vulnerabilities in CheckMK Management Web Console versions 1.5.0 to 2.0.0p9, with detailed disclosure…

docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228

XSS Vulnerability in Rittal

solution

Remote Code Execution vulnerability on ArcSight Logger

PoC for CVE-2020-6207 (Missing Authentication Check in SAP Solution Manager)

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Artica Proxy before 4.30.000000 Community Edition allows SQL Injection.

Artica Proxy before 4.30.000000 Community Edition allows Reflected Cross Site Scripting.

CVE-2020-13159 - Artica Proxy before 4.30.000000 Community Edition allows OS command injection.