
CVE-2022-24637
Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2

Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2

Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python

Plane’s V2 asset subsystem trusted workspace slugs and asset UUIDs without enforcing the right membership checks, which let one authenticated user…

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

Docker-based lab for reproducing CVE-2026-42647, an unauthenticated time-based blind SQL injection in the JoomSport WordPress plugin via the sortf…

Local Docker lab for reproducing CVE-2026-55255, an IDOR vulnerability in Langflow's Responses API. Validates cross-user flow execution in vulnerable…

Pre-Auth RCE in ProFTPD via mod_sql is_escaped_text() bypass (CVE-2026-42167)

Authenticated Command Injection Tool (CVE-2022-31898) - HACKCONRD 2026.

POC for CVE-2020-2883