
Check-WP-CVE-2020-35489
Python script to detect WordPress sites vulnerable to CVE-2020-35489 in Contact Form 7, allowing unrestricted file uploads. Scans domains or lists…

Python script to detect WordPress sites vulnerable to CVE-2020-35489 in Contact Form 7, allowing unrestricted file uploads. Scans domains or lists…

Proof-of-concept exploit for CVE-2023-27163, a Server-Side Request Forgery (SSRF) vulnerability in request-baskets up to v1.2.1. Includes automated…

Exploit script for CVE-2021-41277, an arbitrary file read vulnerability in Metabase, allowing unauthorized access to sensitive files.

Batch verification script for CVE-2021-43798 in Grafana, written in Go, with 48 built-in checks to identify vulnerable instances and download the…

Proof-of-concept for absolute path disclosure in Veno File Manager 4.4.9 via an unauthenticated GET request to a debug script, revealing the server's…

Proof-of-concept exploit for CVE-2017-15715, demonstrating Apache HTTPD mod_php file upload bypass using a trailing newline character to execute…

PoC and verification toolkit for CVE-2026-28286, an arbitrary file write vulnerability in ZimaOS, exploiting API misconfiguration to write files…

Proof-of-concept exploit for CVE-2026-37073: unauthenticated SMTP email abuse via incorrect access control in Veno File Manager 4.4.9.

Proof-of-concept exploit for CVE-2024-53617: stored XSS in LibrePhotos enabling account takeover via malicious HTML file upload with IDOR bypass.

Easy to configure Honeypot for Blue Team

CVE-2026-30691: Stored Cross-Site Scripting (XSS) in @cyntler/react-doc-viewer

This repo contains a script to automatically test sites for vulnerability to the Heartbleed Bug (CVE-2014-0160) based on the input file for the urls.

Stored XSS in InterMind iMind Server through 3.13.65 allows any user to hijack another user's session by sending a malicious file in the chat.

Proof-of-concept exploit for CVE-2026-37748, an unrestricted file upload vulnerability in Visitor Management System 1.0 leading to remote code…

A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file /admin/settings.php. The…

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

Decrypts passwords stored in SOS JobScheduler (S)FTP profiles by exploiting the use of the profile name as the 3DES encryption key, enabling recovery…

Reflected XSS exploit for Online Exam Mastering System 1.0 with PoC payloads, impact analysis, and mitigation guidance for security testing and…