
CVE-2025-44136
Proof-of-concept exploit for unauthenticated reflected XSS in MapTiler Tileserver-php v2.0 via the 'layer' GET parameter, enabling arbitrary HTML/JS…

Proof-of-concept exploit for unauthenticated reflected XSS in MapTiler Tileserver-php v2.0 via the 'layer' GET parameter, enabling arbitrary HTML/JS…

A Cross-Site Request Forgery (CSRF) vulnerability exists in the administrator profile update functionality of CarRentalMS v2.0. The affected endpoint…

Exploit for CVE-2026-2406 targeting Terrminus Authentication Gateways, using temporal dispersion to bypass fingerprinting and behavioral AI,…

CVE-2024-57428: PHPJabbers Cinema Booking System v2.0 suffers from stored XSS, enabling persistent JavaScript injection for phishing and malware…

Proof-of-concept exploit for CVE-2025-25614, an incorrect access control vulnerability in Unifiedtransform v2.0 allowing teachers to modify fellow…

CVE-2024-57429: PHPJabbers Cinema Booking System v2.0 is vulnerable to CSRF, allowing attackers to escalate privileges by forging requests on behalf…

Automated PoC exploit for CVE-2024-9326, a SQL injection vulnerability in PHPGurukul Online Shopping Portal v2.0, enabling security professionals to…

Proof-of-concept demonstrating incorrect access control in Unifiedtransform v2.0, allowing students to modify exam rules via the /exams/edit-rule…

CVE-2024-57427: PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected XSS, allowing session hijacking and phishing attacks.

Proof-of-concept for stored XSS in Unifiedtransform v2.0's Create Assignment function, demonstrating remote code execution via malicious PDF upload…

PoC of CVE-2025-46203

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could…

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Automated exploit tool for CVE-2018-9206 (jQuery File Upload) with single/multi-target scanning, Tor proxy support, and output logging for…