
CVE-2022-30190
Exploit artifact for CVE-2022-30190, targeting remote code execution in the Microsoft Support Diagnostic Tool (MSDT) through crafted Office documents.

Exploit artifact for CVE-2022-30190, targeting remote code execution in the Microsoft Support Diagnostic Tool (MSDT) through crafted Office documents.

A Docker-based research environment for analyzing CVE-2025-59532, a path traversal vulnerability in OpenAI Codex CLI that allows arbitrary file write…

Proof-of-concept exploit for a stored cross-site scripting (XSS) vulnerability in the HTML Include and Replace macro for Confluence Server, allowing…

Proof-of-concept for a reflected XSS vulnerability in Sourcecodester Task Reminder System 1.0, demonstrating authenticated remote code execution via…

Lightweight Python scanner for CVE-2021-2109 that checks target URLs for the specific vulnerability with minimal dependencies.

Nuclei template for CVE-2024-6648, an absolute path traversal vulnerability in the Prestashop ApPage Builder plugin. Enables automated detection and…

Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First…

A critical zero-day vulnerability CVE‑2025‑53770 has been actively exploited in the wild against on-premises Microsoft SharePoint Server. Dubbed…

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…

Repository dedicated to the analysis and exploitation of CVE-2023-26048 in Jetty 9.4.31, providing vulnerability research and proof-of-concept code…

Proof-of-concept exploit for CVE-2017-5007, demonstrating the vulnerability and its impact.

This script exploits and performs an SSRF (Server-Side Request Forgery) and Timing Attack against the SAP BusinessObjects Launchpad (CVE-2020-6308).…

Docker environment and exploit the CVE-2023-30212 vulnerabilityVE-2023-30212 is a security vulnerability that affects versions of OURPHP prior to or…

An issue was discovered in cPanel before 11.109.9999.116. Cross-Site Scripting can occur on the cpsrvd error page via an invalid webcall ID.

Proof-of-concept exploit for CVE-2024-1651, demonstrating insecure deserialization to achieve remote code execution. Provides a fast, easy-to-use…

Proof-of-concept exploit for CVE-2020-14882 in Oracle WebLogic Server, demonstrating remote code execution via crafted HTTP requests to the console…

Repository dedicated to CVE-2021-34428, a vulnerability in Jetty 9.4.31. Provides a patched or vulnerable version for analysis and testing of the…

Proof-of-concept demonstrating stored cross-site scripting (XSS) in Minical 1.0.0 via the Room Status edit note feature, with step-by-step…