
CVE-2023-34051
VMware Aria Operations for Logs CVE-2023-34051

VMware Aria Operations for Logs CVE-2023-34051

CVE-2023-43261 - Credential Leakage Through Unprotected System Logs and Weak Password Encryption

Proof-of-concept exploit for FortiOS authentication bypass (CVE-2024-55591) that allows unauthenticated access to system logs via WebSocket on…

Exploit for CVE-2017-14262 targeting Samsung NVR devices: extracts admin MD5 password hash via unauthenticated CGI request and logs in with the hash…

Scans host lists for GeoServer endpoints vulnerable to CVE-2023-25157 SQL injection, verifies exposed paths with keyword checks, and logs confirmed…

it is script that enables Telnet on routers by sending a specially crafted request. The script allows users to specify the router's URL, Telnet port,…

Proof-of-concept exploit for CVE-2026-4802, a command injection vulnerability in Cockpit's system logs UI, enabling arbitrary command execution and…

is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies

Proof-of-concept CSRF exploit for One Identity Cloud Access Manager 8.1.3 that logs out victims via a crafted HTML form submission.

This binary POC automates the exploitation of CVE-2024-36991 by sending crafted curl requests to a vulnerable Splunk instance. It retrieves sensitive…

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

Dockerized vulnerable lab demonstrating CVE-2024-2083 in ZenML, a path traversal vulnerability in the step logs API allowing arbitrary file read.

Proof-of-concept exploit for CVE-2023-32315, a path traversal vulnerability in Openfire's setup/log.jsp, enabling unauthenticated access to sensitive…

Unauthenticated arbitrary file upload exploit for WooCommerce Return Refund and Exchange plugin (CVE-2022-4047). Scans targets, uploads webshell, and…

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

Remote Code Execution vulnerability on ArcSight Logger

Proof-of-concept exploit for CVE-2025-31324, a remote code execution vulnerability in SAP NetWeaver, with Shodan dorks for target discovery and…

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack