
CVE-2020-9496
Proof-of-concept exploit for CVE-2020-9496 (Apache OFBiz) with nuclei template integration and step-by-step vulnerable environment setup for security…

Proof-of-concept exploit for CVE-2020-9496 (Apache OFBiz) with nuclei template integration and step-by-step vulnerable environment setup for security…

Multiple Reflected XSS in TastyIgniter v3.0.7 Restaurtant CMS

Proof-of-concept exploit for CVE-2024-4040 (CrushFTP) providing unauthenticated file read, credential decryption, and remote code execution via…

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a…

Open Web Analytics 1.7.3 - Remote Code Execution

Proof-of-concept exploit script for command injection (CVE-2026-27626) in OliveTin's password argument handling, enabling RCE via crafted API…

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php

Proof-of-concept exploit for CVE-2024-42327, an SQL injection vulnerability in Zabbix frontend API allowing non-admin users to execute arbitrary SQL…

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

Modern Events Calendar Lite <= 7.33.0 — Unauthenticated SQL Injection

Proof-of-concept for CVE-2021-40352 in OpenEMR 6.0.0, demonstrating unauthorized access to patient messages via parameter manipulation in…