

Proof of Concept for Stored-XSS on Vulnerable WP-Statistics Plugin known as CVE-2025-9816

CVE-2022-42889 (a.k.a. Text4Shell) RCE Proof of Concept

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code…

Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes…

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Dippy's chat component, allowing attackers to access and tamper with other…

Documentation of CVE-2025-51858, a self-XSS vulnerability in ChatPlayground.ai enabling JWT theft and account hijacking, combined with an IDOR in…


CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns

Windows Oracle Database Attack Toolkit

AzureGoat : A Damn Vulnerable Azure Infrastructure