This is your work, valued
My account is not always useful to you
POC-CVE-2025-24813. his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.
195CVE-2025-0282-Ivanti-exploit. CVE-2025-0282 is a critical vulnerability found in Ivanti Connect Secure, allowing Remote Command Execution (RCE) through a buffer overflow exploit.
53Bypass-authentication-GitHub-Enterprise-Server. The authentication bypass vulnerability in GitHub Enterprise Server (GHES) allows an unauthorized attacker to access an instance of GHES without requiring pre-authentication. The vulnerability affects all GHES versions prior to 3.13.0.
51ZeroHuntAI. ZeroHuntAI is an advanced source code vulnerability scanner designed to detect potential vulnerabilities in your codebase. It combines static code analysis with pattern matching and AI evaluation to identify security issues before they can be exploited.
24TomcatKiller-CVE-2025-31650. A tool designed to detect the vulnerability **CVE-2025-31650** in Apache Tomcat (versions 10.1.10 to 10.1.39)
20CVE-2025-6218-WinRAR-Directory-Traversal-RCE. CVE-2025-6218 is a directory traversal vulnerability in WinRAR that allows an attacker to place files outside the intended extraction directory when a user extracts a specially crafted
18Microsoft-Edge-Information-Disclosure. CVE-2024-30056 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
17CVE-2024-44000-LiteSpeed-Cache. CVE-2024-44000 is a vulnerability in the LiteSpeed Cache plugin, a popular WordPress plugin. This vulnerability affects session management in LiteSpeed Cache, allowing attackers to gain unauthorized access to sensitive data.
16Apache-OFBiz-Directory-Traversal-exploit.
16MetaInjector. MetaInjector is a tool designed to test security by injecting malicious payloads (such as XSS, SQL Injection, remote code execution, etc.) into image metadata. The tool supports image formats such as JPEG, PNG, and SVG
14PoC-for-CVE-2024-7014-Exploit. Proof of Concept (PoC) for CVE-2024-7014 (EvilVideo) Exploit
12-CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server. This vulnerability could allow an attacker to take complete control of a vulnerable Confluence server. This could allow the attacker to steal data, modify data, or disrupt the availability of the server.
11XSS-Payloads-for-Bypassing-Filters-and-Firewalls. Cross-Site Scripting (XSS) is a common vulnerability that allows attackers to inject malicious scripts into web pages viewed by users. In response, many websites use filtering techniques and firewalls to block these malicious scripts. However, sophisticated attackers can bypass these filters by using various encoding techniques
11WordPress-XStore-theme-SQL-Injection. (CVE-2024-33559) The XStore theme for WordPress is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query
9CVE-2026-24858-FortiCloud-SSO-Authentication-Bypass. CVE-2026-24858 FortiCloud Single Sign On (SSO) a factory default enabled feature once you register any FortiGate/FortiManager/FortiAnalyzer contains a critical authentication bypass flaw.
9Vulnerability-detection-functions. Vulnerability detection funcVulnerability-detection-functions Vulnerability Detection Functionality The script currently focuses on detecting cross-site scripting (XSS) vulnerabilities in web links. Additional functions will be developed to detect vulnerabilities so you can incorporate them into your script.
8CVE-2025-27533-Exploit-for-Apache-ActiveMQ. exploit for CVE-2025-27533, a Denial of Service (DoS) vulnerability in Apache ActiveMQ
8403Ruaad. 403Ruaad is a tool to bypass the 403 Forbidden error condition that you may encounter when trying to access certain resources on the web.
6CVE-2024-56512-Apache-NiFi-Exploit. A tool to exploit the CVE-2024-56512 vulnerability in Apache NiFi, which allows unauthorized access to sensitive data through improperly secured APIs.
4FreeRDP-Out-of-Bounds-Read-CVE-2024-32459-. The FreeRDP - Out-of-Bounds Read (CVE-2024-32459) vulnerability concerns FreeRDP, a free implementation of Remote Desktop Protocol. FreeRDP-based clients and servers using a version of FreeRDP prior to version 3.5.0 or 2.11.6 are vulnerable to out-of-bounds reading12. Versions 3.5.0 and 2.11.6 correct the problem
4CVE-2025-23048-POC. Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used across virtual hosts with different `SSLCACertificateFile` directives.
4-CrushFTP-11.1.0---Directory-Traversal. A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
3Cisco-Firepower-Management-Center-Exploit. Python
3CVE-2025-27007-OttoKit-exploit. exploiting CVE-2025-27007, a critical unauthenticated privilege escalation vulnerability in the OttoKit (formerly SureTriggers) WordPress plugin
2CVE-2025-27210_NodeJS_Path_Traversal_Exploit. (PoC) CVE-2025-27210, a precise Path Traversal vulnerability affecting Node.js applications running on Microsoft Windows. This vulnerability leverages the specific way Windows handles reserved device file names
2Poc-CVE-2024-57040. CVE-2024-57040 is a security vulnerability found in certain TP-Link TL-WR845N router models. Specifically, it involves a "hardcoded" password for the router's root account. This means a default, unchanging password is built into the router's software.
2absholi7ly.
1PHP-Injection-in-M4-PDF-Extensions. CVE-2023-50029: PHP Injection Vulnerability in M4 PDF Extensions Module
10day.today.archive. An archive of 0day.today exploits
1