
CVE-2023-30092
Proof-of-concept exploit for SQL injection in Sourcecodester Online Pizza Ordering System 1.0. Demonstrates remote code execution and denial of…

Proof-of-concept exploit for SQL injection in Sourcecodester Online Pizza Ordering System 1.0. Demonstrates remote code execution and denial of…

Proof-of-concept for CVE-2023-46450: authenticated stored cross-site scripting (XSS) vulnerability in the Add Supplier function of Sourcecodester…

Proof-of-concept exploit for CVE-2023-46449: IDOR in Sourcecodester inventory management system v1.0 password change function enabling remote account…

Reflected Cross-Site Scripting in Snipe-IT CSV Import Workflow

lib/G/functions.php in Chevereto 1.0.0 through 1.1.4 Free, and through 3.13.5 Core, allows an attacker to perform bruteforce attacks without…

Advanced dork Search & Mass Exploit Scanner

Bash simulator to control a server using PHP system functions.

Single-file PHP webshell providing remote file management, command execution, bind/reverse shell, database connectivity, and process control for…

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

Automated blind XPath injection exploitation tool with optimized data retrieval, built-in OOB HTTP server, and interactive REPL shell for file system…

🎩 🤟🏻 [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak -…

Exploit script for Cisco ASA path traversal (CVE-2018-0296) that extracts system information, active sessions, and valid usernames from vulnerable…

Standalone RCE exploit for Acunetix WVS 10 that delivers a Meterpreter reverse shell with SYSTEM privileges via staged payload download and execution.

🐱💻 👍 Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123…

Prototype anti-automation system demonstrating bot detection, malformed HTML traps, invisible links, and signature-reversing honeypot techniques for…

Shell script exploit for CVE-2020-25213 targeting unauthenticated arbitrary file upload in WordPress File Manager plugin (<6.9), enabling full system…

Proof-of-concept exploit for Fortinet FortiClient EMS SQL injection vulnerability (CVE-2023-48788). Demonstrates unauthenticated SQL injection to…

Proof-of-concept exploit for CVE-2023-43261 targeting Milesight industrial routers. Demonstrates credential leakage via unprotected system logs and…