
unicorn
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Detailed penetration test report demonstrating unauthenticated path traversal (CVE-2019-11447) in WordPress Simple Backup plugin, including…

Bash proof-of-concept exploit for CVE-2026-33017 in Langflow, triggering a reverse shell callback to a netcat listener.

Proof-of-concept implementation for CVE-2026-33017, demonstrating the vulnerability for authorized security testing and research.

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

Proof-of-concept exploit for CVE-2025-68613, an authenticated remote code execution vulnerability in N8N. Executes arbitrary bash commands on…

A fast, simple, recursive content discovery tool written in Rust.

Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9

Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Simple POC for CVE-2026-39987

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

cve-2019-5420 POC simple ruby script

Bypass Authentication

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Adobe Magento SessionReaper LFI Vulnerability

Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.

Missing Authorization to Unauthenticated File Modification