
AbxOverflow
Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

Detailed CVE-2024-55187 advisory with proof-of-concept for a remote code execution vulnerability in phpIpam, exploiting path poisoning and PHAR file…

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top…

All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection

PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0

CVE-2020-26259: XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has…

Proof-of-concept exploit for authenticated unrestricted file upload leading to remote code execution in MachForm up to version 21, with detailed…

Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security,…

Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

CVE-2020-26259 &&XStream Arbitrary File Delete

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

Advisory for textract ⌯⌲ 15 000 weekly downloads

Tainacan <= 0.21.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

CVE-2024-3553: Tutor LMS <= 2.6.2 - Missing Authorization vulnerability allowing authenticated attackers to enable user registration