
CVE-2021-21239
Exploit for CVE-2021-21239: SAML signature validation bypass in pysaml2/Redash. Forges SAML responses with embedded public keys to impersonate users…

Exploit for CVE-2021-21239: SAML signature validation bypass in pysaml2/Redash. Forges SAML responses with embedded public keys to impersonate users…

A standalone Blind XSS Script.

full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

Advisory and technical write-up for CVE-2026-18782, a critical SQL injection in TREX MES web API endpoints enabling auth bypass, data theft, and RCE…

[CVE-2017-9822] DotNetNuke Cookie Deserialization Remote Code Execution (RCE)

Proof of concept for the command injection vulnerability affecting the ZTE MF286R router, including an RCE exploit.

Vbullettin RCE - CVE-2025-48827

Improved code of Daniele Scanu SQL Injection exploit

CVE-2025-26865: FreeMarker Server-Side Template Injection via the "ecommerce" plugin in Apache OfBiz

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina

VMware Aria Operations for Logs CVE-2023-34051

CVE-2022-30190 | MS-MSDT Follina One Click

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Exploit toolkit for CVE-2021-40444 MSHTML remote code execution, featuring DLL payload generation, Office document crafting, and lateral movement…

Proof-of-concept exploit for CVE-2020-16152: LFI-to-RCE in Aerohive/Extreme Networks HiveOS via PHP string truncation and log poisoning, enabling…

Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell,…