
CVE-2025-58434-PoC
CVE-2025-58434 Proof of Concept

CVE-2025-58434 Proof of Concept

CVE-2025-58434 Flowise <= 3.0.5 and earlier allows account takeover via unauthenticated forgot-password token. CVE-2025-59528 lowiseAI Custom MCP…

Authentication bypass exploit for Joomla CVE-2023-23752 that leaks administrator credentials and MySQL configuration from vulnerable versions…


Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

Python Exploit for CVE: 2018-9276

Python PoC for CVE-2024-36042 authentication bypass in Silverpeas < 6.3.5. Features version detection, multi-threaded user enumeration, message…

Proof-of-concept exploit for CVE-2023-23752 (Joomla 4.0.0-4.2.8) that extracts usernames and passwords via an information disclosure vulnerability.

A Python proof-of-concept exploit for CVE-2019-15107 - an unauthenticated remote code execution vulnerability in Webmin versions 1.890 through 1.920.

Exploit for CVE-2024-46987

Exploit for CVE-2025-2304 | Camaleon CMS versions < 2.9.1

Exploit for CVE-2025-2304

Proof-of-concept exploit for CVE-2024-24919, a Check Point path traversal allowing arbitrary file read (e.g., /etc/shadow) via crafted HTTPS POST…

Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

Proof-of-concept exploit for CVE-2025-22963, a CSRF vulnerability in Teedy v1.11 allowing account takeover via user information change endpoint.

CVE-2020-35847, CVE-2020-35848 : Account Takeover

Detailed disclosure of CVE-2025-22963, a CSRF vulnerability in Teedy <= v1.11 enabling account takeover via forced user information changes.

This is an exploit for CVE-2024-23346 that acts as a "terminal" (tested on chemistry.htb)