
CVE-2025-15602-PoC
Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation

Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation

Short Python script for exploiting CVE-2025–24000 based on this blog post: https://medium.com/@security_56355/from-subscriber-to-admin-reproducing-cve…

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)


Combined PoC for CVE-2025-28434 and CVE-2025-59528


CVE-2025-58434 and CVE-2025-59528 chain POC

CVE-2026-24415 - OpenSTAManager Affected by XSS in modifica_iva.php via righe parameter

CVE-2025-67875 - ChurchCRM has stored XSS via Person Property Assignment Leading to Admin Session Hijacking

CVE-2025-67876 - ChurchCRM has Stored XSS in Group Role Name Leading to Admin Session Hijacking

This repository provides a practical comparison of breach intelligence, dark web monitoring, and identity exposure services, with a focus on factors…

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)

Authenticated Stored Cross-Site Scripting (XSS) in IndieWeb WordPress Plugin

Authenticated Stored Cross-Site Scripting (XSS) in Contact List Plugin

CVE-2026-34197

CVE-2025-64446


PoC for CVE-2025-14340: Admin account takeover in Payara Server