

PoC exploit generator for CVE-2025-64512: creates malicious pickle.gz payloads and PDFs to trigger remote code execution via pdfminer.six…

Authenticated remote code execution exploit for OpenSTAManager <=2.9.8 via malicious ZIP upload with shell command injection in .p7m filenames.

CVE-2024-37032 (Probllama) PoC for Ollama ≤0.1.33: path traversal and arbitrary file write via model digest handling, leading to automated privilege…

Proof-of-concept exploit for CVE-2026-0740: unauthenticated arbitrary file upload to RCE in Ninja Forms File Uploads plugin for WordPress. Includes…

Automated scanner and exploit for CVE-2026-27384, an unauthenticated RCE in W3 Total Cache via mfunc/eval() injection. Features auto-detection, 48…

Automated scanner for CVE-2026-5718, an unauthenticated file upload to RCE vulnerability in the DnD Upload CF7 WordPress plugin. Exploits non-ASCII…

Python-based exploit for CVE-2021-3129 enabling remote code execution on vulnerable Laravel applications with automatic log path detection and…

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

Proof-of-concept exploit for CVE-2026-7393: unrestricted file upload in Pizzafy Ecommerce System 1.0 allowing authenticated administrators to upload…

Proof-of-concept for authenticated remote code execution in ClipBucket via PHP code injection in update_launch.php. Includes web shell deployment and…

Proof-of-concept exploit for CVE-2025-49132 enabling unauthenticated remote code execution in Pterodactyl Panel <= 1.11.10 via locale parameter…

Proof-of-concept for CVE-2025-27237: local privilege escalation in Zabbix Agent for Windows via OpenSSL configuration file hijacking, with PoC DLLs…

Exploit script for CVE-2024-51793 targeting unauthenticated arbitrary file upload in WordPress Computer Repair Shop plugin, enabling remote code…

Authenticated file upload remote code execution exploit for Clinic's Patient Management System (CPMS). Uploads a malicious PHP shell via profile…

Proof-of-concept exploit for CVE-2025-55182, demonstrating remote code execution via multipart form data injection targeting Node.js vm and…

WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload

CIBELES AI <= 1.10.8 - Unauthenticated Arbitrary File Upload