
CVE-2024-6330
GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization

GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization

Exploit for CVE-2025-28915: WordPress ThemeEgg ToolKit arbitrary file upload vulnerability allowing remote Web Shell deployment. Includes…

Detailed CVE-2021-31856 report with PoC and code analysis for a SQL injection vulnerability in Meshery's pattern file API, enabling unauthenticated…

CVE-2022-37207 POC

Proof-of-concept for SQL injection in Portabilis i-Educar 2.8.0, demonstrating unauthenticated database access via the getDocuments endpoint with…

Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…


Remote code execution Vulnerability in QloApps (version 1.6.0.0)

Go-based proof-of-concept exploit for CVE-2018-6574, demonstrating remote code execution via crafted requests to vulnerable Go applications.

GHSA-4cx5-89vm-833x/CVE-2024-52800

Super Backup & Clone - Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload

Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin…

Proof-of-concept script demonstrating unauthenticated remote code execution in Sourcecodester Poultry Farm Management System via the vulnerable…

Proof-of-concept exploit for CVE-2024-4577 enabling remote code execution in vulnerable PHP versions 8.1-8.3. Includes customizable arguments for…

Proof of Concept for CVE-2020-14295.

CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

Proof-of-concept exploit for CVE-2020-0601 (CurveBall) demonstrating ECC certificate validation bypass to spoof trusted CA and sign arbitrary…

Proof-of-concept exploit for CVE-2018-11235, a remote code execution vulnerability in Git submodules. Demonstrates exploitation of malicious…