
CVE-2024-0195-SpiderFlow
CVE-2024-0195 Improper Control of Generation of Code ('Code Injection')

CVE-2024-0195 Improper Control of Generation of Code ('Code Injection')

WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型…

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall

Proof-of-concept exploit for CVE-2025-53367, a vulnerability in the DjVuLibre library. Demonstrates exploitation of a memory corruption bug in DjVu…

Vulnerability Description

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning,…

Proof-of-concept demonstration for CVE-2020-28948 and CVE-2020-28949, PHP Archive_Tar path traversal and arbitrary file write vulnerabilities.

Proof-of-concept exploit and technical write-up for CVE-2023-6553, an unauthenticated PHP file inclusion vulnerability enabling remote code execution…

Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the…

Multi-layer security framework for AI agent ecosystems. Provides pre-installation skill auditing, file integrity monitoring, runtime protection, and…

PoC & dokumentasi untuk CVE-2026-7275: Moodle Google Drive Repository (repository_googledocs) — Path Traversal / Arbitrary File Write yang dapat…

Proof-of-concept exploit for PrivateBin Local File Inclusion (CVE-2025-64714) via template cookie path traversal, with detection and RCE chaining…

Unauthenticated Local File Inclusion

Proof-of-concept exploit for CVE-2024-5932, a PHP object injection vulnerability in the GiveWP WordPress plugin, enabling unauthenticated remote code…

Proof-of-concept for CVE-2025-60655: Remote Code Execution via unrestricted file upload bypassing client-side JavaScript validation, enabling…

Unauthenticated Arbitrary File Upload in EventPrime Plugin

tar-fs file write/overwrite vulnerability

Detailed analysis of CVE-2025-61686, a path traversal vulnerability in React Router's file session storage, including root cause, attack scenarios,…