
CVE-2025-50286
Authenticated RCE exploit for Grav CMS via plugin upload, demonstrating arbitrary PHP code execution and reverse shell.

Authenticated RCE exploit for Grav CMS via plugin upload, demonstrating arbitrary PHP code execution and reverse shell.

Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

POC for CVE-2026-21858

In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution

FOGProject Authentication bypass CVE-2025-58443 Exploit

Unverified Password Change (CWE-620)

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…

Authenticated SQL injection to command execution on Cacti 1.2.12

Web CTF challenge highlighting moodle CVE-2025-26529 (in 2 flavors)

Go-based exploit tool for CVE-2022-40684 (Fortinet authentication bypass). Automates SSH key injection for authorized penetration testing and…

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM (HTML Injection)

CVE-2024-46879 - Tiki CMS Reflected Cross-Site Scripting (XSS) Vulnerability

WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution

Docker-based lab for CVE-2024-27198 TeamCity authentication bypass. Includes exploit reproduction, IoC hunting with Sigma/Suricata rules, and…

CVE-2022-3552 RCE with detailed exploitation steps

An improved POC exploit based on the reported CVE on exploitdb