
CVE-2025-5304
PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation

PT Project Notebooks 1.0.0 - 1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation
Unauthenticated Privilege Escalation to Administrator via Role Form Field

CVE-2025-15495 - Arbitrary File Upload Leading to Remote Code Execution (RCE)

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass

Pluck v4.7.18 - Remote Code Execution (RCE)

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

CVE-2025-31161

Python exploit for CVE-2015-6967 targeting Nibbleblog with a reverse shell payload. Executes authenticated remote code execution via file upload…

Proof-of-concept exploit for CVE-2023-24249, an arbitrary file upload vulnerability in laravel-admin, enabling web shell deployment for penetration…


Updated exploit for CVE-2021-22911 (Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated))

Wordpress Video Gallery - YouTube Gallery and Vimeo Gallery Plugin SQL Injection

GitHub repository for CVE-2023-3460 POC

Authenticated reflected XSS in TastyIgniter version v3.2.2.

Demonstrates the x-middleware-subrequest header bypass in Next.js 13.4.19, allowing unauthorized access to protected routes. Includes setup, normal…

Zoo Management System 1.0 - Stored Cross-Site-Scripting (XSS)

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE
