
CVE-2025-52385
Studio 3T v.2025.1.0

Studio 3T v.2025.1.0

FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行

Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to…

Automated exploit for CVE-2025-66034, chaining path traversal and XML injection in fontTools varLib to achieve unauthenticated remote code execution…

Wordpress IgniteUp plugin < 3.4.1 allows unauthenticated users to arbitrarily delete files on the webserver possibly causing DoS.

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

EXPLOIT CVE-2026-8832


Details about the Blind RCE issue(SPX-GC) in SPX-GC

