
CVE-2018-7600
CVE-2018-7600 POC (Drupal RCE)

CVE-2018-7600 POC (Drupal RCE)

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action

Proof-of-concept exploit for JetBrains TeamCity that performs unauthenticated remote code execution via agent polling protocol deserialization,…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Fermion, an electron wrapper for Frida & Monaco.

This extension will help you to detect GET/POST based XSS vulnerability in any website easily


Minimal Python proof-of-concept for CVE-2026-64638 that sends a crafted HTML/JSONP XSS payload to WordPress wp-login.php.

Exploits CVE-2026-64638 to convert cross-site scripting into shell access on vulnerable web applications, automating payload delivery and…

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

This Burp Suite extension allows for the automatic creation and deletion of an upstream SOCKS5 proxy on popular cloud services.

Exploits targeting vBulletin.

POC BLH Magelang CSIRT 2026 by babyrootkid


Jenkins Git Client RCE CVE-2019-10392_Exp


