
poc-CVE-2026-23489
Proof of concept (POC) for CVE-2026-23489 GLPI "Fields" plugin <= 1.23.2

Proof of concept (POC) for CVE-2026-23489 GLPI "Fields" plugin <= 1.23.2
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research

The Clickjacking Exploit Detector uses webpage scanning techniques to identify potential vulnerabilities and provide analysis of those elements.

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.

Apache Flink Dashboard未授权访问-远程代码命令执行

Exploits CVE-2026-64638 to convert cross-site scripting into shell access on vulnerable web applications, automating payload delivery and…

Jenkins Git Client RCE CVE-2019-10392_Exp


This repo describe how to exploit unrestricted file upload vulnerability on SiteMagic CMS 4.4.2

This is Metasploit module who exploit the command injection vulnerability in control center of the agent Tesla.

Adobe Experience Manager Childlist Selector - Cross-Site Scripting

Rubbish SQLI that requires Admin

Authenticated Remote Command Execution – pfSense <= 2.1.3

Got My CVE Published CVE-2023-41575

automated SQL injection for QCubed profile.php file

Men Salon Management System Using PHP and MySQL

unauthenticated booking logic flaw in Easy!Appointments v1.5.1 causing denial of service.

Python exploit for CVE-2025-70559 targeting an upload directory bypass/remote code execution; run with LHOST and LPORT to establish a reverse shell.