
CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability
Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

CVE-2026-6765 · Test only FormAutofill handlers exposed in Firefox

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

CVE-2026-72550 — Friendica Unauthenticated Stacked-Query SQL Injection PoC (CVSS 9.8 Critical)


The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4

Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications

A standalone Blind XSS Script.




CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept

Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using…


WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…