


CVE-2022-31245: RCE and domain admin privilege escalation for Mailcow

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

PoC for CVE-2025-14340: Admin account takeover in Payara Server

Takeover of Oracle WebLogic Server

A CSRF POC for Updating the Profile of a Hospital leading to Account Takeover



Mailcow CVE-2022-31138 RCE

CVE-2024–27631 Reference

A standalone Blind XSS Script.

Security checks for your researches


WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

CVE-2019-12836

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

An authenticated Stored Cross-site Scripting (XSS) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file…