
CVE-2026-3300
Exploit for CVE-2026-3300, an unauthenticated stored XSS leading to RCE in Everest Forms Pro WordPress plugin, with a Python script to generate a…

Exploit for CVE-2026-3300, an unauthenticated stored XSS leading to RCE in Everest Forms Pro WordPress plugin, with a Python script to generate a…

Wordpress IgniteUp plugin < 3.4.1 allows unauthenticated users to arbitrarily delete files on the webserver possibly causing DoS.

Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.

Detection scripts for CVE-2023-50164 in Apache Struts2, providing PowerShell and Bash tools to scan for vulnerable versions across file systems and…

Proof-of-concept exploit for CVE-2026-0766, a remote code execution vulnerability in OpenWebUI via tool code injection. Includes command execution,…

Migration,Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file

[PoC] Privilege escalation & code execution via LFI in PwnDoC

Proof-of-concept exploit for CVE-2024-50340 demonstrating Symfony ArgvInput environment variable injection via crafted URL query parameters, enabling…

Go scripts for finding sensitive data like API key / some keywords in the github repository

CVE-2024-37032 (Probllama) PoC for Ollama ≤0.1.33: path traversal and arbitrary file write via model digest handling, leading to automated privilege…

Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

PoC exploit for CVE-2024-52302: unrestricted file upload in common-user-management Spring Boot app leading to remote code execution via…

Technical analysis and proof-of-concept for CVE-2025-69906, an arbitrary file upload vulnerability in Monstra CMS 3.0.4 leading to remote code…

Proof-of-concept exploit for CVE-2023-46694: authenticated remote code execution via arbitrary file upload in Vtenext 21.02 Ckeditor file manager.

Extracts and exports certificate information from digitally signed PE files using Python and pefile, enabling forensic analysis of code-signing…

Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output…

Automated exploit for CVE-2025-66034, chaining path traversal and XML injection in fontTools varLib to achieve unauthenticated remote code execution…

GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization