
CVE-2025-12973
S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.7 - Authenticated (Editor+) Arbitrary File Upload

S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.7 - Authenticated (Editor+) Arbitrary File Upload

Python exploit for CVE-2018-15133, achieving remote code execution on vulnerable Laravel applications via insecure deserialization of encrypted…

Python exploit for CVE-2015-10137 targeting an arbitrary file upload vulnerability in the WordPress N-Media Website Contact Form plugin, enabling…

Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action

Flex QR Code Generator <= 1.2.6 - Unauthenticated Arbitrary File Upload

Proof-of-concept exploit for CVE-2025-49132 enabling unauthenticated remote code execution in Pterodactyl Panel <= 1.11.10 via locale parameter…

Exploit code for Clinic patient management system v1 unauth rce cpms rce CVE-2022-40471

Proof-of-concept exploit for authenticated PHP code injection in ISPConfig <= 3.2.11, enabling remote code execution via unsanitized language file…

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'

Pluck v4.7.18 - Remote Code Execution (RCE)

Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.116 - Authenticated (Administrator+) Arbitrary File Upload

Remote code execution exploit for CVE-2019-11043 targeting Nginx with php-fpm. Includes Go and pre-compiled exploit binaries for testing vulnerable…

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

Proof-of-concept exploit for CVE-2024-10410: unrestricted file upload in Online Hotel Reservation System. Demonstrates bypass of image validation via…

Proof-of-concept exploit for CVE-2017-7504 targeting JBoss 4.x JBossMQ JMS deserialization vulnerability. Includes usage help via -h flag.

CVE-2021-44228