
CVE-2021-24307-all-in-one-seo-pack-admin-rce
Proof-of-concept exploit for CVE-2021-24307, an authenticated admin RCE in All in One SEO Pack <= 4.1.0.1 via PHP unserialization, enabling arbitrary…

Proof-of-concept exploit for CVE-2021-24307, an authenticated admin RCE in All in One SEO Pack <= 4.1.0.1 via PHP unserialization, enabling arbitrary…

Proof-of-concept for stored XSS in SourceCodester CET Automated Grading System 1.0, demonstrating unauthenticated payload injection via student…

Proof-of-concept for a stored XSS vulnerability in Hotel and Tourism Reservation System 1.0, demonstrating unauthenticated injection and admin…

CVE-2026-23550 - Modular DS WordPress Plugin **Unauthenticated Admin Access**

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

Bash script for WordPress user enumeration and automated admin account creation, exploiting CVE-2026-23550 to bypass authentication and achieve…

Exploits Zabbix SQL injection (CVE-2024-42327) to extract admin session and execute commands via API, achieving reverse shell.

Proof-of-concept exploit for CVE-2021-45008, demonstrating privilege escalation from user to admin in Plesk Obsidian 18.0.37 by manipulating a Super…

Proof-of-concept for CVE-2026-7089, a stored XSS in Home Service System PHP 1.0 allowing unauthenticated admin session hijacking via booking form.

Exploit for CVE-2025-59287, injecting WolfShell memory webshell into WSUS servers to achieve remote code execution when the admin console is opened.

A Proof of Concept (PoC) exploit for CVE-2025-70886, a persistent denial-of-service vulnerability in Halo CMS (v2.22.4 and earlier) that allows…

n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)

Exploit for CVE-2023-46747, a remote code execution vulnerability in F5 BIG-IP, allowing unauthorized user creation and command execution.

Authentication Bypass in GoAnywhere MFT

Proof of Concept for CVE-2025-31161 / CVE-2025-2825

CVE-2021-37580的poc


cve-2022-23131