
CVE-2015-8562
Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header

Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

Proof of Concept of Libreoffice file exfiltration vulnerability in Big Blue Button

Proof-of-concept exploit for CVE-2022-22965 in Payara/Glassfish, demonstrating arbitrary file download via web root manipulation. Includes Docker…

CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

CVE-2021-24647 Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login

Commvault Remote Code Execution (CVE-2025-34028) NSE

cve-2020-10977 read and execute

Proof of concept demonstrating Cross-Site Request Forgery (CSRF) on Avaya SCOPIA XT Desktop, allowing admin password change without anti-CSRF token.

A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9

CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys

Python POC for CVE-2025-5095

Repository to exploit CVE-2023-46604 reported for ActiveMQ

Masteriyo - LMS for WordPress <= 1.6.7 - Sensitive Information Exposure

Minimal PoC for CVE-2022-29856

Automated exploit script for CVE-2018-20250 (WinRAR ACE extraction code execution) that generates a malicious archive file embedding a payload into…

Proof-of-concept exploit for CVE-2025-29927 in Next.js 15.2.0, demonstrating a specific web application vulnerability for testing and educational…