
CVE-2026-59827
Metabase CVE-2026-59827 Vulnerability Scanner

Metabase CVE-2026-59827 Vulnerability Scanner

Proof-of-concept exploit for CVE-2026-4802, a command injection vulnerability in Cockpit's system logs UI, enabling arbitrary command execution and…

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

Dockerized vulnerable lab demonstrating CVE-2024-2083 in ZenML, a path traversal vulnerability in the step logs API allowing arbitrary file read.

This binary POC automates the exploitation of CVE-2024-36991 by sending crafted curl requests to a vulnerable Splunk instance. It retrieves sensitive…

CVE-2025-10377

Una herramienta avanzada de escaneo, explotación e interacción remota diseñada para detectar y aprovechar la vulnerabilidad Apache Path Traversal +…

Web CTF challenge highlighting moodle CVE-2025-26529 (in 2 flavors)

Proof-of-concept exploit for CVE-2025-31324, a remote code execution vulnerability in SAP NetWeaver, with Shodan dorks for target discovery and…

Proof-of-concept exploit for FortiOS authentication bypass (CVE-2024-55591) that allows unauthenticated access to system logs via WebSocket on…

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies

it is script that enables Telnet on routers by sending a specially crafted request. The script allows users to specify the router's URL, Telnet port,…

Exploit for CVE-2023-27100 bypassing pfSense anti-brute force protection via crafted X-Forwarded-For headers and anti-CSRF tokens to evade sshguard…

Unauthenticated arbitrary file upload exploit for WooCommerce Return Refund and Exchange plugin (CVE-2022-4047). Scans targets, uploads webshell, and…

VMware Aria Operations for Logs CVE-2023-34051

CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

Proof-of-concept exploit for CVE-2023-32315, a path traversal vulnerability in Openfire's setup/log.jsp, enabling unauthenticated access to sensitive…