
CVE-2025-66417-POC
Proof-of-concept exploit for CVE-2025-66417 demonstrating SQL injection via XML POST request to extract database information from a web application…

Proof-of-concept exploit for CVE-2025-66417 demonstrating SQL injection via XML POST request to extract database information from a web application…

D-LINK DIR-845L is vulnerable to information disclosure via the bsc_sms_inbox.php file.

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

Unauthenticated SQL injection exploit for WordPress versions 2.1.3 to 2.8.2, targeting the Ultimate Member plugin to extract sensitive database…

Exploit for CVE-2015-6668: CV filename disclosure vulnerability in the Job-Manager WordPress plugin. Demonstrates information gathering via path…

Python script to exploit CVE-2019-3403 for scraping user information from vulnerable JIRA instances via the unauthenticated user search API.

Python exploit for CVE-2021-38314 targeting unauthenticated sensitive information disclosure in WordPress Gutenberg Template Library & Redux…

Proof-of-concept exploit for CVE-2024-51132, an XML External Entity (XXE) injection vulnerability in HAPI FHIR core libraries, enabling SSRF and…

Document Library Lite <= 1.1.6 - Missing Authorization to Sensitive Information Exposure | CVE-2025-11174

Python exploit script for CVE-2019-9053 targeting CMS Simple. Automates vulnerability exploitation and information gathering for penetration testing…

Exploit script for authenticated blind SQL injection in MachForm up to v19, using time-based techniques to extract database information from the…

Proof-of-concept exploit for CVE-2023-23752 (Joomla 4.0.0-4.2.8) that extracts usernames and passwords via an information disclosure vulnerability.

CPAS audit management information system has SQL injection vulnerability(CVE-2025-57529)

A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an…

An issue in HSC Cybersecurity HSC Mailinspector version 5.2.17-3 has been identified, allowing a remote attacker to obtain sensitive information via…

Description: SQL Injection vulnerability in HSC Cybersecurity HSC Mailinspector v.5.2.17-3 allows a remote attacker to obtain sensitive information…

MxChat – AI Chatbot for WordPress <= 2.5.1 - Unauthenticated Information Exposure