
CVE-2024-6651
POC (XSS) -> CVE-2024-6651

POC (XSS) -> CVE-2024-6651

Exploit for CVE-2024-46987

CVE-2024-46987 - Camaleon CMS LFI Exploit

Reflected XSS proof-of-concept for CMSimple_XH 1.8 with unauthenticated script injection via unsanitized path segments, including CVSS 6.1 scoring…

Proof-of-concept for authenticated stored XSS in Autoptimize < 3.1.14, exploiting insufficient attribute sanitization in image preload tag generation.

Proof-of-concept exploit for CVE-2025-2294, a critical LFI vulnerability in Kubio AI Page Builder for WordPress. Includes a Python scanner, nuclei…

This repository has details on a vulnerability found with the "vCard" plugin for CraftCMS 3.

CVE-2023-38831 - WinRAR

Detailed technical analysis and proof-of-concept exploit for WordPress RCE vulnerabilities CVE-2019-8942 and CVE-2019-8943, demonstrating LFI-to-RCE…

CVE-2023-4220 PoC Chamilo RCE

Proof-of-concept exploit for Fonoster LFI vulnerability (CVE-2024-43035)

This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical…

Exploit Code for CVE-2019-11447 aka CuteNews 2.1.2 Avatar upload RCE (Authenticated)

PoC and exploit for Apache HTTP Server 2.4.49 path traversal vulnerability (CVE-2021-41773) with Docker setup, curl-based exploitation commands, and…

Unauthenticated Remote Code Execution with default Imagick

OpenEMR Security issue

Django SQL injection vulnerability

Proof-of-concept exploit for CVE-2021-29447, an authenticated XXE vulnerability in WordPress 5.6-5.7. Includes lab setup, malicious WAV generation,…