
MAGNOLIA-8281
MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS

MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS
CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

CVE-2022-22947 reproduce

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all…

CVE-2021-44228

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual…

PoC for CVE-2017-0075

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

Proof-of-concept for CVE-2025-52099, an integer overflow in SQLite 3.50.0's setupLookaside function leading to heap-buffer-overflow.

Proof-of-concept exploit for CVE-2019-5413, a remote code execution vulnerability in Apache NetBeans. Demonstrates exploitation via crafted XML…

C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes…

In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a…

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

Vulnerabilidad CVE-2024-24926 afecta al tema Brooklyn de WordPress

Proof-of-concept exploit for CVE-2019-5413 targeting NetBeans IDE, demonstrating remote code execution via crafted project files.

cve-2018-6574 @pentesterlab

Proof-of-concept exploit for CVE-2024-22411 targeting the Avo admin panel. Demonstrates vulnerability exploitation in Ruby-based web applications.