
Bad_Hoist-WriteUp
A Writeup for Sleirsgoevy's version of the Exploit Implementation of CVE-2018-4386 by Fire30 called Bad_Hoist

A Writeup for Sleirsgoevy's version of the Exploit Implementation of CVE-2018-4386 by Fire30 called Bad_Hoist

A WebKit exploit using CVE-2018-4441 to obtain RCE on PS4 6.20.

On October 4, 2021, Apache HTTP Server Project released Security advisory on a Path traversal and File disclosure vulnerability in Apache HTTP Server…

Shell-based exploit script for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Server and Data Center,…

CVE-2018-6574 this vulnerability impacts Golang go get command and allows an attacker to gain code execution on a system by installing a malicious…

Proof-of-concept demonstrating CVE-2026-17351 SQL injection bypass in pgAdmin 4's AI Assistant via sqlparse/PostgreSQL lexer differential, including…

Docker-based vulnerable lab and detailed PoC report for CVE-2023-25157/25158 SQL injection in GeoServer & GeoTools, with 4 verified attack vectors…

A comprehensive vulnerability scanner for CVE-2025-13780, a Remote Code Execution (RCE) vulnerability in pgAdmin 4 versions ≤ 8.14.

Scripts to detect and exploit CVE-2024-9014 OAuth2 authentication bypass in pgAdmin 4, including vulnerability checking and OAuth2 configuration…

Sistema NetAdmin IAM 4 é vulnerável a Cross Site Scripting (XSS), no endpoint /BalloonSave.ashx

Proof-of-concept exploits for CVE-2024-41453 and CVE-2024-41454 demonstrating stored XSS and malicious file upload vulnerabilities in ProcessMaker 4…

Payload Generation Framework

Atlassian Jira Server/Data Center 8.4.0 - Arbitrary File read (CVE-2021-26086)

Atlassian Confluence Server 7.5.1 Pre-Authorization Arbitrary File Read vulnerability (CVE-2021-26085)

CVE-2020-13942 POC + Automation Script

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

A PoC exploit for CVE-2015-2166 - Directory Traversal Vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP)

Apache Solr < 8.8.2 Server Side Request Forgery