
CVE-2026-55040
Exploit code for CVE-2026-55040, it can create auth header for any validate account.

Exploit code for CVE-2026-55040, it can create auth header for any validate account.


PoC exploit for CVE-2022-35914 — GLPI v.10.0.2 htmLawed command injection, command execution, and reverse shell support.

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted…



Exploit script for CVE-2026-9198 targeting IBM Langflow, providing proof-of-concept code to validate vulnerabilities and support authorized security…

The poc of CVE-2025-59528

my poc for CVE-2026-53787

Authenticated remote code execution exploit for Windows Admin Center via WinREST/PowerShell invokeCommand; takes credentials and runs arbitrary…

PoC exploit for CVE-2026-15038 in InfiniteWP Client WordPress plugin: bypasses authentication on Multisite, binds attacker RSA key, escalates to…

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.



PoC for testing reflected XSS in Swagger UI via CVE-2019-1749; sends crafted payloads and verifies vulnerable endpoints with minimal setup.

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

A wordlist of API names for web application assessments

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…