
CVE-2025-67923
JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

PoC exploit for a CSRF vulnerability in Apache Roller v6.1.2 profile update endpoint. Includes HTML form exploit code to demonstrate unauthorized…


Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型…

Cybersecurity Capstone Project completed during the NCSC Nashama CyberCamp 11, delivered in collaboration with IT Security C&T. The project…

Proof-of-concept exploit for CVE-2025-63708, a stored XSS vulnerability in AI Font Matcher. Demonstrates session cookie theft via unsanitized font…

WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability

CVE-2019-8449 Exploit for Jira v2.1 - v8.3.4

Go-based MITM exploit demo for OpenSSL CVE-2014-0224 (CCS Injection) targeting RC4-SHA cipher, with server/client proxy setup for testing TLS…

Exploit for CVE-2020-11998 targeting Apache ActiveMQ 5.15.12, enabling remote code execution via crafted messages to the vulnerable message broker.

XSS Vulnerability via File Upload in Ferozo Webmail Application

Reproduction of iOS 11 bug CVE-2018-4110

CVE-2018-12597

Security research lab for CVE-2025-55183 and CVE-2025-55184 in React Server Components

Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

Stored XSS proof-of-concept for PPC (Belden) ONT 2K05X router firmware v1.1.9_206L, with reproduction steps and mitigation guidance for the…