Advanced Search
Search Filters
Results
CVE-2026-94130
CVE-2026-94130Unauthenticated SQL injection in Joomla YouTube Gallery (joomlaboat.com, com_youtubegallery) ≤ 5.7.2 — video search/sort on the public yg_api endpoint...
CVE-2026-94132
CVE-2026-94132AcyMailing Enterprise for Joomla 11.1.0: POP3 mailbox actions save MIME attachments without extension checks to media/com_acym/upload/, enabling RCE ...
cve-2026-97163-payload
CVE-2026-97163CVE-2026-97163 PoC payload (UP plugin Joomla remote code installation)
CVE-2026-97160
CVE-2026-97160CVE-2026-97160 PoC for Joomla UP (lomart.fr): privileged {up php=} shortcode eval code injection in versions 5.0.0–5.2.0 and 6.0.0–6.0.29 (fix 5.2.1 /...
CVE-2026-97161
CVE-2026-97161CVE-2026-97161 PoC: Joomla UP (lomart.fr) unauthenticated path traversal / arbitrary file read via ajax-view (≤6.0.29). Fingerprints plugin, probes co...
CVE-2026-97163
CVE-2026-97163CVE-2026-97163 PoC: Joomla UP (lomart.fr) unauthenticated GitHub mini-install / remote action deployment (≤6.0.29). Detects plugin version, probes com...
CVE-2026-82901
CVE-2026-82901CVE-2026-82901 PoC: WordPress Ultra Addons for Contact Form 7 ≤3.5.50 unauth file upload via signature field when PDF Generator is enabled → wp-conten...
CVE-2026-61500
CVE-2026-61500CVE-2026-61500 Rejetto HFS predictable PRNG session forgery to RCE PoC and Docker lab
CVE-2026-41089-POC
CVE-2026-41089CVE-2026-41089 LongLogon: pre-auth CLDAP (UDP/389) stack buffer overflow crasher for unpatched Windows Server 2025 Netlogon (lsass 0xc0000409). Stdlib...
CVE-2026-29053
CVE-2026-29053CVE-2026-29053 - Ghost CMS 6.19.0 - Authenticated Remote Code Execution via Malicious Theme
POC-WP-CORE-CVE-2026-93485
CVE-2026-93485Laboratorio pedagógico de CVE-2026-93485 (Comment2Shell): stored XSS no autenticado en WordPress core vÃa wpautop - RCE, con demo del root cause auto-...
CVE-2026-13249
CVE-2026-13249Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit P...
zf9-ghostlock
CVE-2026-43499CVE-2026-43499 (GhostLock) exploit for ASUS Zenfone 9 (SM8475, GKI 5.10.205) + KernelSU late-load. Authorized research.
CVE-2024-37054_PoC_HTB_SmartHire
CVE-2024-37054MLFlow unsafe deserialization (CVE-2024-37054) written for HTB machine - SmartHire
CVE-2026-18143
CVE-2026-18143Unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via public AJAX afrfq_submit_quote_via_popup — unsafe move_upl...
CVE-2026-65660-Poc
CVE-2026-65660Malicious Register Directive Code Injection Exploit
Comment2Shell
CVE-2026-93485Comment2Shell is a zero click pre auth RCE exploit for WordPress CVE-2026-93485. An anonymous comment plants stored XSS that fires when an admin views...
NovaShyld_Task_3
CVE-2011-2523Penetration testing report and PoC on Metasploitable2 target, demonstrating CVE-2011-2523 vsFTPd v2.3.4 exploitation via Metasploit.
CVE-2024-3651-exploit
CVE-2024-3651Simple app to demonstrate CVE-2024-3651
SOC336-CVE-2025-21298-Investigation
CVE-2025-21298LetsDefend SOC lab investigating CVE-2025-21298 Windows OLE Zero-Click RCE exploitation.