
CVE-2026-35584
Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

Authenticated remote code execution exploit for Zen Cart via SQL injection in admin module editing. Proof-of-concept for CVE-2021-3291.

Serverless AITM Simulation Framework for Entra ID and M365

PoC for CVE-2026-56423: MISP deleteSelection broken access control (CWE-862, contributor hard-deletes other orgs' Event Reports/Sharing Groups, CVSS…

SQL injection in QuerySet.annotate(), aggregate(), and extra()

Write-up and proof of concepts for CVE-2021-30862, 1-click RCE bug in iOS iTunes U

Educational demonstration of CVE-2017-17917 SQL injection in Rails, with step-by-step replication and secure coding mitigation using parameterized…

Python exploit for Cacti RCE (CVE-2024-29895) via command injection in cmd_realtime.php. Includes reconnaissance dorks for Google, Shodan, and FOFA.

CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds

SQL injection via unsanitized QuerySet.order_by() input


Proof-of-concept exploit for CVE-2024-3217, an unauthenticated SQL injection in the WP Directory Kit WordPress plugin, allowing extraction of…

Technical analysis of a reflected XSS vulnerability in the Tag Groups WordPress plugin before 2.2.0, covering root cause, attack flow, impact,…

An issue was discovered in cPanel before 11.109.9999.116. Cross-Site Scripting can occur on the cpsrvd error page via an invalid webcall ID.

PoC for CVE-2023-2579

PoC for CVE-2023-2123

Proof-of-concept exploit for SQL injection in Sourcecodester Cab Management System 1.0, demonstrating arbitrary SQL execution via the id parameter in…