
CVE-2021-40905
Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

AdmirorFrames Joomla! Extension < 5.0 - HTML Injection

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

Burp Suite extension for detecting CVE-2022-42889 (Text4Shell) vulnerability via passive scanning of HTTP requests and responses.

(Wordpress) Ninja Forms File Uploads Extension <= 3.0.22 – Unauthenticated Arbitrary File Upload

Proof-of-concept exploit for CVE-2024-44902, a deserialization vulnerability in ThinkPHP v6.1.3–v8.0.4 enabling remote code execution via crafted…

CVE-2025-55182-Exploiter Google Chrome Extension. nextjs vulnerability #nextjscve

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

This tool is a Proof of Concept (PoC) intended for security research and educational purposes only. Using this tool on systems without explicit…


Burp Suite extension for detecting CVE-2025-55182 (React2Shell) unsafe deserialization vulnerability. Features safe digest check, PoC redirect mode,…

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

Responsive FileManager v.9.9.5 vulnerable to CVE-2022-46604.

Proof-of-concept exploit for CVE-2024-6778, a Chromium sandbox escape via a malicious browser extension, achieving code execution on privileged WebUI…

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…
