
CVE-2025-67923
JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…

PoC script for HTTP/2 Rapid Reset (CVE-2023-44487) that sends crafted HTTP/2 streams to trigger denial-of-service conditions on vulnerable servers,…

Proof-of-concept for CVE-2026-19500, a DoS vulnerability in the SureForms WordPress plugin that exhausts server resources via oversized key-value…

Proof-of-concept for stored cross-site scripting in Redaxo's mediapool (CVE-2024-50803), demonstrating malicious SVG upload on versions below 5.18.0…

Proof-of-concept exploit for CVE-2026-59310, demonstrating remote path traversal via crafted syslog messages to write arbitrary log files on VMware…

CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

Proof-of-concept exploit for Apache Struts S2-072 (CVE-2026-73633), demonstrating CPU and memory exhaustion by sending crafted JSON requests to the…

mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut

Exploit for CVE-2026-64638, a pre-authentication reflected XSS in WordPress login, enabling injection of malicious JavaScript into /wp-login.php…

Proof-of-concept HTML page that reproduces CVE-2019-10070, a cross-site scripting vulnerability in Apache Atlas, for validation and defensive testing.

Exploit for CVE-2025-6440: unauthenticated arbitrary file upload in WooCommerce Designer Pro WordPress plugin, enabling RCE via malicious PHP upload.

Bash exploit for CVE-2026-23550 that triggers unauthenticated WordPress admin login via crafted REST API request to Modular Connector's…

Python proof-of-concept exploit for CVE-2026-7458, an unauthenticated authentication bypass in PickPlugins User Verification WordPress plugin via…

WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

Exploit code for CVE-2026-55040, it can create auth header for any validate account.