
CVE-2020-5902
POC code for checking for this vulnerability. Since the code has been released, I decided to release this one as well. Patch Immediately!

POC code for checking for this vulnerability. Since the code has been released, I decided to release this one as well. Patch Immediately!

Zimbra unrar vulnerability. Now there are already POC available, it is safe to release our POC.

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Print Archive System v2015 release 2.6

CVE-2026-9806 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting CTI Transmute versions prior to the patched release.

Coordinated disclosure of CVE-2025-52204: reflected XSS and HTML injection in Znuny OTRS customer.pl endpoint. Includes technical summary, affected…


Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

PoC for CVE-2026-66066 in Ruby on Rails

Proof-of-concept exploit for CVE-2024-23897 enabling unauthenticated arbitrary file read on Jenkins servers. Supports authenticated sessions, proxy,…

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Proof-of-concept exploit for CVE-2021-29156, an LDAP injection vulnerability in ForgeRock OpenAM v13.0.0, enabling character-by-character brute force…

Proof-of-concept exploit for CVE-2019-13720, a Chrome browser vulnerability. Includes a demonstration video and a released exploitation tool for…

CVE-2023-22527

包括能执行的命令探测和一键getshell(需要服务器部署服务)

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)