
CVE-2026-35584
Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

Tangalanga: the Zoom conference scanner hacking tool

PoC exploit for CVE-2020-11800, a command injection in Zabbix Server via malicious agent auto-registration, with Python-based payload delivery and…

Analyze and track OAuth 2.0, OIDC, and Microsoft Entra ID tokens from Burp, mitmproxy, or Chrome DevTools captures. Visualize token lifecycles,…

Search for information related to domain: Emails - IP addresses - Sub-Domains - Information on WEB technology - Type of Firewall - NS and MX records.

Technical analysis of a reflected XSS vulnerability in the Tag Groups WordPress plugin before 2.2.0, covering root cause, attack flow, impact,…

An issue was discovered in cPanel before 11.109.9999.116. Cross-Site Scripting can occur on the cpsrvd error page via an invalid webcall ID.

PoC for CVE-2023-2579

PoC for CVE-2023-2123

Proof-of-concept for CVE-2023-7173, a stored XSS in Hospital Management System 1.0, with Docker setup and reproduction steps.

Proof-of-concept for CVE-2026-36957, a denial-of-service vulnerability in Dbit Router firmware via HTTP flood on the Boa web server, causing resource…

Detailed CVE-2025-12758 disclosure with PoC demonstrating Unicode variation selector bypass in validator.js isLength(), including root cause…

Proof-of-concept demonstrating a stored XSS vulnerability in FreelanceHub's profile bio field, with step-by-step reproduction and impact analysis.

Reflected XSS vulnerability disclosure with PoC script and remediation guidance for an online appointment booking system. Includes vulnerable…

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password…

Python exploit script and Nuclei template for CVE-2023-37979, a reflected XSS vulnerability in the Ninja-forms WordPress plugin, enabling automated…

Exploit for CVE-2023-37621 targeting unauthorized access in Fronius Datalogger Web 2.0.5-4, allowing attackers to retrieve sensitive device…