Advanced Search
Search Filters
Results
wp2shell-Exploit-Waf-Bypass
CVE-2026-63030WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab
CVE-2026-64638-PoC-Exploit
CVE-2026-64638🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment & ad...
teamcity-CVE-2026-63077-pcap
CVE-2026-63077teamcity teamcity-CVE-2026-63077 exploitation pcap
CVE-2026-18953
CVE-2026-18953PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter
CVE-2026-64638-POC
CVE-2026-64638CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC
ResetNightmare-impacket
CVE-2026-27912CVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoC
CVE-2026-60004-poc-gitea
CVE-2026-60004CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection
CVE-2026-64638-PoC-XSS2Shell-
CVE-2026-64638XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template
XSS2Shell-CVE-2026-64638
CVE-2026-64638CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (X...
Zapscape
CVE-2026-64561Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.
aarif450.github.io
CVE-2026-64561Exploit KVM/x86 guest-to-host escape CVE-2026-64561 with Zapscape, a proof-of-concept demonstrating hypervisor vulnerability.
poc-h2-CVE-2026-71554
CVE-2026-71554PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)
CVE-2026-58048-PoC-Exploit
CVE-2026-58048👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe ...
poc-CVE-2026-23489
CVE-2026-23489Proof of concept (POC) for CVE-2026-23489 GLPI "Fields" plugin = 1.23.2
ghostlock-honor-aak
CVE-2026-43499GhostLock (CVE-2026-43499) exploit adapted for Honor AAK-AN00 (MagicOS 10, kernel 6.6.89-android15)
SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit
CVE-2026-47301Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path traver...
couchdb-exploit
CVE-2017-12635This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-126...