
CVE-2024-10629
GPX Viewer <= 2.2.8 - Authenticated (Subscriber+) Arbitrary File Creation

GPX Viewer <= 2.2.8 - Authenticated (Subscriber+) Arbitrary File Creation
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced…

In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a…

Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a craftedpayload to the…

Exploit for CVE-2019-3396, a path traversal and RCE vulnerability in Confluence Server, enabling unauthorized file read and remote code execution.

Ultimate Before After Image Slider & Gallery – BEAF <= 4.6.10 - Authenticated (Admin+) Arbitrary File Upload via beaf_options_save

Instantio - Wordpress Plugin <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload via ins_options_save

Swift Performance Lite <= 2.3.7.1 - Unauthenticated Local PHP File Inclusion via 'ajaxify'

Hotfix for file deletion to to code execution vulnerability in WordPress

Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses…

SigFlip is a tool for patching authenticode signed PE files (exe, dll, sys ..etc) without invalidating or breaking the existing signature.

Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

Exploit script for CVE-2021-22204, an ExifTool RCE via malicious DjVu files, with manual exploitation steps and reverse shell payloads.

CVE-2022-32119 - Arox-Unrestricted-File-Upload

WordPress Elementor 3.6.0 3.6.1 3.6.2 RCE POC

All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection

[PoC] Privilege escalation & code execution via LFI in PwnDoC