
CVE-2023-27163-Request-Baskets-Local-Ports-Bruteforcer
PoC and internal port brute-forcer for CVE-2023-27163

PoC and internal port brute-forcer for CVE-2023-27163

Unauthenticated Arbitrary File Read via Absolute Path


A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

It is a simple script to automate internal port scanning dueto SSRF in requests-baskets v 1.2.1. this script can also assisst in solving 'SAU'…

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…

This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an…


There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions …

Microsoft Edge Elevation of Privilege Vulnerability


peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

PhantomJS uses internal module: webpage, to open, close, render, and perform multiple actions on webpages, which suffers from an arbitrary file read…

This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access…