
CVE-2024-23346
PoC of the vulnerability CVE-2024-23346

PoC of the vulnerability CVE-2024-23346

Stored XSS proof-of-concept for OpenKM notes section, demonstrating a javascript: bypass of sanitization rules, with CVSS 3.1 scoring and…

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

Tries to exploit a WordPress vulnerability (CVE-2018-6389) which can be used to cause a Denial of Service.

Coordinated disclosure of CVE-2025-52204: reflected XSS and HTML injection in Znuny OTRS customer.pl endpoint. Includes technical summary, affected…

Educational demonstration of CVE-2022-46169: unauthenticated remote code execution in Cacti ≤1.2.22 via authorization bypass and command injection.…

Step-by-step lab demonstrating exploitation of CVE-2017-12635 (privilege escalation) and CVE-2017-12636 (remote code execution) against Apache…

This project provides a fully functional demonstration of CVE-2025-55182 (React2Shell) - a critical Remote Code Execution vulnerability in React…

Exploit Server-Side Request Forgery (SSRF) vulnerabilities through nginx configurations. Enables testing and exploitation of SSRF in web applications.

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling…

Nuxt3 Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability

Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution

Educational analysis of CVE-2021-44228 (Log4Shell) with PoC scripts, attack vector breakdown, and mitigation guidance for understanding and testing…

We hope to reproduce CVE-2021-41773 to deepen our understanding of real-world cybersecurity vulnerabilities so that we can be knowledgeable about…

Technical analysis of CVE-2025-55182 (React2Shell RCE vulnerability)

Public disclosure and writeup of CVE-2021-44593, an unauthenticated SQL injection in Simple College Website leading to arbitrary file upload and…

Exploit for the vulnerability of Ultimate Member Plugin.

TikiWiki 21.2 allows to edit templates without the use of a CSRF protection.