
CVE-2024-6387
Proof-of-concept exploit script for CVE-2024-6387, a critical unauthenticated remote code execution vulnerability in OpenSSH. Designed for security…

Proof-of-concept exploit script for CVE-2024-6387, a critical unauthenticated remote code execution vulnerability in OpenSSH. Designed for security…

Integer Overflow in Cart Logic in SimplCommerce allows remote attackers to manipulate product quantities and total prices via crafted inputs that…

Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field

CVE-2025-25965 is a newly discovered CSRF vulnerability in the Phpgurukul Online Banquet Booking System v1.2, allowing remote attackers to change a…

Educational lab demonstrating a deserialization vulnerability in Microsoft SharePoint that enables remote code execution, with a hands-on…

Lightweight Python PoC to detect CVE-2020-0618 Remote Code Execution vulnerability in Microsoft SQL Server Reporting Services via SOAP API path…

Proof-of-concept exploit for CVE-2024-32004, a Git remote code execution vulnerability, demonstrating exploitation via a malicious upload-pack filter.

CVE-2006-0450. phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users…

Little recap of the log4j2 remote code execution (CVE-2021-44228)

A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users…

Documentation of CVE-2025-28074: a reflected Cross-Site Scripting (XSS) vulnerability in phpList 3.6.3 due to improper input sanitization in lt.php,…

Essay (and PoCs) about CVE-2021-41773, a remote code execution vulnerability in Apache 2.4.49 🕸️

wp2shell — WordPress Core Pre-Auth RCE (CVE-2026-63030 + CVE-2026-60137). Exploit toolkit + remediation.

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning,…

CVE-2026-1357 — WPvivid Backup & Migration ≤ 0.9.123 Unauthenticated RCE Exploit

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

Apache HTTP/2 double-free vulnerability PoC (CVE-2026-23918)

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)