
CVE-2024-24919
Proof-of-concept exploit script for CVE-2024-24919 that scans target URLs via HTTP POST requests, analyzes responses for unauthorized access or data…

Proof-of-concept exploit script for CVE-2024-24919 that scans target URLs via HTTP POST requests, analyzes responses for unauthorized access or data…

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

An example exploit for CVE-2017-7376

YZMCMS v3.7最新版xss漏洞 CVE-2018-8078

Trivy example module for WordPress

🔴 CVE-2026-22794 - Appsmith Password Reset Account Takeover via Origin Header Injection | PoC Exploit + Nuclei Template

Go tool and Nuclei template for testing James Kettle's (CVE-2025-32094) HTTP/1.1 must die: the desync endgame

Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046

CVE-2023-31664 WSO2

Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)

POC CVE-2024-46982

CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…

PoC exploit for CVE-2026-49975 HTTP/2 Bomb DoS vulnerability. Demonstrates HPACK indexed reference bomb combined with flow-control window stall to…

Proof-of-concept exploit for an arbitrary file write vulnerability in Halo CMS backup restoration, enabling RCE via plugin JAR replacement or…

PoC and test server

CVE-2026-14856 TastyIgniter v4.3.0