
CVE-2025-27407
Local lab and proof-of-concept exploit for CVE-2025-27407, targeting GitLab's GraphQL introspection schema loader via the Direct Transfer HTTP path.…

Local lab and proof-of-concept exploit for CVE-2025-27407, targeting GitLab's GraphQL introspection schema loader via the Direct Transfer HTTP path.…

proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198

Python-based exploit for CVE-2025-30208 targeting Vite dev server arbitrary file read. Supports single-target detection, custom file paths, system…

Golang PoC exploit for CVE-2025-12139 targeting the Integrate Google Drive WordPress plugin. Extracts sensitive OAuth credentials (Client ID, Secret,…

Automated exploitation toolkit for CVE-2025-24813 targeting Apache Tomcat insecure session deserialization. Features multi-target scanning, gadget…

Mass RCE exploit script for CVE-2025-55182 (React2Shell) targeting Next.js applications. Automates payload injection, command execution, and output…

Proof-of-concept exploit for time-based blind SQL injection in Commend VoIPRec G8-VOIPREC device, targeting the vulnerable Code parameter for…

Educational exploit for CVE-2015-0311, a use-after-free vulnerability in Adobe Flash Player, targeting Linux/Firefox to demonstrate memory corruption…

a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.

CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool