
CVE-2018-14699
Unauthenticated Blind Command injection in the enable_user function of DroboAccess v 2.1

Unauthenticated Blind Command injection in the enable_user function of DroboAccess v 2.1

Proof-of-concept exploit for CVE-2024-34102, demonstrating exploitation of a specific vulnerability for security testing and research purposes.

Write-up and proof of concepts for CVE-2021-30862, 1-click RCE bug in iOS iTunes U

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

Documentation of CVE-2025-65300: a stored Cross-Site Scripting (XSS) vulnerability in the Coohom SaaS platform's Account Settings profile address…

"Once upon a time, the Castle of Reactland trusted all Flight messages... until The Imposter arrived." A storytelling CVE-2025-55182 (React2Shell)…

This is POC of CVE-2024-29671

Proof of concept for stored cross-site scripting (XSS) in Abacre Retail Point of Sale 14.0.0.396, demonstrating injection via Name and Surname fields…

A Rust implementation of the POC for CVE-2017-7269, targeting the WebDAV service in Microsoft Internet Information Services (IIS) 6.0.

POC of CVE-2018-8718 + tool

exploit tool of CVE-2018-11564

Proof of Concept Exploit for CVE-2021-35956, AKCP sensorProbe - 'Multiple' Cross Site Scripting (XSS)

📄Official disclosure of CVE-2022-4556 — Stored Cross-Site Scripting (XSS) vulnerability in SOGo Webmail v5.7.1, discovered by Ashkan Rafiee and…

A minimal reproduction of an AngularJS <textarea> XSS vulnerability on IE (tracked as CVE-2022-25869).

Proof of Concept for React2Shell vulnerability

Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class,…

A simple bash script that exploits CVE-2021-22205 against vulnerable instances of gitlab

a proof of concept of CVE-2024-53677