
IsolatedAnarchy-Public
Proof-of-concept exploit for CVE-2026-87492, a Chromium site isolation bypass using a patched renderer and MojoJS to demonstrate cross-origin data…

Proof-of-concept exploit for CVE-2026-87492, a Chromium site isolation bypass using a patched renderer and MojoJS to demonstrate cross-origin data…

Python PoC for CVE-2026-77770, an unauthenticated arbitrary WordPress option deletion flaw in the miniOrange 2FA plugin (<= 6.3.0) via the…

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

CVE-2026-2332 and 4 more 2026 Jetty CVEs: which does your Jetty (or Spring Boot) build hit, and does the fixed version Jetty names even exist on…

Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery

This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965).

Proof-of-concept implementation for CVE-2026-33017, demonstrating the vulnerability for authorized security testing and research.

Proof-of-concept exploit for CVE-2026-41096, demonstrating the vulnerability and providing a reproducible test case for security researchers and…

Proof-of-concept exploit scripts for CVE-2026-63642 and CVE-2026-63643, SSRF vulnerabilities in MagicMirror²'s Calendar module allowing…

Python proof-of-concept exploiting CVE-2026-77578, an authenticated path traversal in Xibo CMS that reads arbitrary local files via crafted XML…

Proof-of-concept exploit for CVE-2026-13181 affecting Telerik web components, demonstrating remote code execution via crafted requests.

PHP proof-of-concept for CVE-2026-42613, demonstrating exploitation of the referenced vulnerability.

This is my own written POC on the xmlrpc-pingback vulnerabiity found on wordpress. CVE-2025-54352.

Proof-of-concept for CVE-2026-79303, a critical boolean-blind SQL injection in Kaiten affecting order_by and order_direction parameters, with…

Proof-of-concept exploit for CVE-2026-34159, demonstrating the vulnerability and providing exploitation code for security testing and research.

Proof-of-concept for CVE-2026-79387, an authenticated SQL injection in PbootCMS user management allowing arbitrary field updates and account takeover.

StyleSmuggler (CVE-2026-75650) IOC toolkit for Magento Open Source and Adobe Commerce. Detect compromised stores, Rust implants, PHP web shells,…

Proof-of-concept exploit code for CVE-2024-38077, a remote code execution vulnerability in Windows Remote Desktop Licensing Service. Backup copy, not…