Advanced Search
Search Filters
Results
SOC335-CVE-2024-49138-Exploitation-Detected
CVE-2024-49138LetsDefend SOC lab investigating CVE-2024-49138 exploitation and related malicious activity.
CVE-2026-mikrotik-poc
CVE-2026-86060CVE-2026-86060 - CVE-2026-67279 - CVE-2026-67276 RouterOS SSH
CVE-2026-59310-POC
CVE-2026-59310CVE-2026-59310-POC 仅用于自测,请勿用于攻击
CVE-2007-2447
CVE-2007-2447Samba 3.0.20 username map script command injection exploit — reverse shell via SMB authentication, built from scratch in Python using impacket. No Met...
ghostlock-mrx-w09
CVE-2026-43499CVE-2026-43499 (GhostLock) port: working root on the Huawei MatePad Pro MRX-W09 (Kirin 990, EMUI 11, Linux 4.14.116) - disassembly-proven write primit...
Kestra-cve-2026-53576
CVE-2026-53576End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common ...
cve-2023-25690-smuggler
CVE-2023-25690Python exploit for CVE-2023-25690 — Apache HTTP Request Smuggling via CRLF injection in mod_rewrite/mod_proxy. Built and tested against TryHackMe'...
CVE-2026-89055
CVE-2026-89055Unauthenticated authorization bypass in Customer Reviews for WooCommerce ≤ 5.120.0: holders of a public /cusrev/{formId}/ review link can POST cr_loca...
CVE-2026-93399
CVE-2026-93399Unauthenticated IDOR in Bookly ≤ 28.2: bookly_get_form_id + bookly_render_complete leak any order’s bookly_order token; bookly_add_to_calendar exposes...
CVE-2026-14281
CVE-2026-14281Unauthenticated privilege escalation in WordPress WAWP (Automation Web Platform) ≤ 4.8.6 via public REST signup and unsanitized wawp_custom_fields → a...
CVE-2026-87902_PoC
CVE-2026-87902Proof of concept for vulnerability CVE-2026-87902 in Wordpress
EXPLOIT-CVE-2026-87902
CVE-2026-87902Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template - LFI - RCE condicional)....
CVE-2026-72001-Pangolin-Cross-Org-Auth-Bypass
CVE-2026-72001PoC for CVE-2026-72001 — Pangolin 1.22.0 cross-organization resource authentication bypass via the share-link access-token endpoint (CWE-639, CVSS 8....
CVE-2026-94609
CVE-2026-94609CVE-2026-94609: Writeup and POC
CVE-2026-12227-visualcomposer-lfi-poc
CVE-2026-12227CVE-2026-12227 - Visual Composer = 45.16.0 unauthenticated LFI via vcv-template (CVSS 9.8): Docker validation lab, safe-oracle PoC, nuclei template. R...
CVE-2010-2075
CVE-2010-2075UnrealIRCd 3.2.8.1 backdoor exploit — reverse shell via AB; trigger, built from scratch in Python using raw sockets. No Metasploit.
CVE-2023-49070
CVE-2023-49070Apache OFBiz XML-RPC pre-auth deserialization RCE PoC (CVE-2023-49070) — auth bypass + ysoserial gadget chain via /webtools/control/xmlrpc
CVE-2026-12227
CVE-2026-12227CVE-2026-12227 (CVSS 9.8): WordPress Visual Composer Website Builder ≤45.16.0 — unauthenticated local file inclusion via vcv-template. Educational PoC...