
CVE-2026-19490
NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

Reflected XSS via search GET Parameter in Phoca Download

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

Damn Small XSS Scanner

Damn Small SQLi Scanner

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

Exploit for CVE-2025-64512 to get a reverse shell.

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

Gogs service Exploit and get the root user

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

Proof-of-concept for unauthenticated SQL injection in Hotel and Tourism Reservation System 1.0, demonstrating database extraction via the tour…

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…