
CVE-2025-2304
A critical mass assignment vulnerability in Camaleon CMS (< 2.9.1) allows authenticated low-privileged users to elevate their privileges to…

A critical mass assignment vulnerability in Camaleon CMS (< 2.9.1) allows authenticated low-privileged users to elevate their privileges to…

A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692

This project is a Python script that exploits the CVE-2023-24489 vulnerability in ShareFile. It allows remote command execution on the target server.…

A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check…





A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.

Worklenz version 2.1.5 Stored Cross-Site Scripting (XSS)


Python script to exploit CVE-2020-35391 on Tenda F3 V3/V4 routers, enabling unauthorized download of configuration, flash, and syslog files.

A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.

This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a…

The Outlook HTML Leak Test Project

RCE in NPM VSCode Extension