
CVE-2023-41425-RCE-WonderCMS-4.3.2
Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Proof-of-concept and technical writeup for CVE-2025-59382, an unauthenticated password reset URL injection in QNAP NAS that enables a…

Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC)…

Proof of concept for CVE-2024-37383

PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script

POC to test CVE-2024-39929 against EXIM mail servers

VanillaForum 2.6.3 allows stored XSS.

Newscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input.




🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting

This repository documents CVE-2026-48849, a Stored Cross-Site Scripting (XSS), HTML Injection, and CSS Injection vulnerability discovered in…

A PoC exploit for CVE-2021-22873 - Revive Adserver Open Redirect Vulnerability.

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.