
cve-2025-66398
Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…


Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Ruby 4.0 Universal RCE Deserialization Gadget Chain - Draft or TODO

CS50's Introduction to Cybersecurity final project on React2Shell (CVE-2025-55182)

Reproduces CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with PoC code, root-cause analysis, impact assessment, and mitigation guidance…

Technical analysis of CVE-2025-55182 (React2Shell), covering vulnerability mechanics, root cause, controlled PoC testing, impact, and mitigation…

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

CVE-2026-64638 - Draft or TODO



This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in…

Security research project

This project demonstrates the publicly disclosed CVE-2018-9995 vulnerability found in multiple embedded DVR devices.

Security research project — SQL Injection vulnerability exploitation and mitigation