
CVE-2020-14965
TP-LINK Multiple HTML Injection Vulnerabilities

TP-LINK Multiple HTML Injection Vulnerabilities

Stored XSS via Location Title in DPCalendar Free

Reflected XSS via AngularJS Sandbox Escape Expressions in IPSwitch WS_FTP Server 8.6.0

Proof-of-concept demonstrating SQL injection in HotelDruid v3.0.5, with steps to exploit vulnerable parameters for data retrieval and remote code…

Java PoC for WebLogic CVE-2020-14645 Coherence deserialization RCE. Hosts a malicious class via LDAP and triggers remote code execution on vulnerable…

Exploit for CVE-2024-47176 targeting CUPS printing service vulnerability. Enables remote code execution and privilege escalation on affected…

Proof-of-concept exploit for CVE-2017-3078, a memory corruption vulnerability in Adobe Flash Player ATF module enabling arbitrary code execution on…

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

Python exploit for Apache HTTP Server 2.4.49 path traversal and remote code execution (CVE-2021-41773), enabling LFI and RCE on vulnerable servers.

Critical CVE-2025-4322 exploit for Firefox on Windows enabling sandbox escape and arbitrary code execution. Includes download link and technical…

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

Systematic reverse engineering of Cisco ASA's lina binary to discover and analyze memory corruption vulnerabilities, including CVE-2025-20333 and…

Exploit for Apache HTTP Server 2.4.49 path traversal and remote code execution vulnerability (CVE-2021-41773), enabling LFI and RCE on vulnerable…

Code review analysis for CVE-2023-4762, focusing on identifying and understanding the vulnerability through source code inspection.

Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First…

🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability…

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Proof-of-concept exploit for CVE-2023-49314 demonstrating code injection in Asana Desktop on macOS via Electron Fuses, with automated vulnerability…