
CVE-2023-22515
Step-by-step exploit walkthrough for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Server and Data Center,…

Step-by-step exploit walkthrough for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Server and Data Center,…

Detailed analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Data Center…

Reproducible Docker lab for CVE-2017-20192 (Formidable Forms < 2.05.03 stored XSS) with automated PoC script for unauthenticated exploitation and…

Proof of concept demonstrating Cross-Site Request Forgery (CSRF) on Avaya SCOPIA XT Desktop, allowing admin password change without anti-CSRF token.

Proof-of-concept exploit for CVE-2023-40000 targeting WordPress LiteSpeed Cache plugin versions < 5.7.0.1. Supports check and attack modes, with XSS…

Proof-of-concept for a stored XSS vulnerability in Bagisto admin panel, demonstrating SVG upload with malicious JavaScript and providing mitigation…

Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload…

Advisory for CVE-2025-65742 — Newgen OmniDocs LDAP Admin BFLA

Proof-of-concept demonstrating command injection in NETIS WF2409E router's ping and traceroute functions, allowing arbitrary command execution via…

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent…

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

Exploit for Zabbix SAML SSO bypass (CVE-2022-23131) enabling unauthorized admin access by forging session cookies.

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

Python exploit for CVE-2022-32199, enabling authenticated admin users to delete arbitrary files on ScriptCase <= 9.9.008 via directory traversal.

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

Automated exploit for CVE-2020-6287 targeting SAP NetWeaver AS JAVA authentication bypass. Creates admin users via LM Configuration Wizard.…

Proof-of-concept exploit for CVE-2024-0566, a post-authenticated time-based SQL injection in Smart Manager 8.27.0 WordPress plugin. Demonstrates…