
CVE-2026-64640
Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

MxChat – AI Chatbot for WordPress <= 2.5.1 - Unauthenticated Information Exposure

Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

Exploit for CVE-2024-12849, an arbitrary file read vulnerability in WordPress Error Log Viewer plugin. Downloads sensitive files via unauthenticated…

Proof-of-concept exploit for authenticated arbitrary file read via directory traversal in WordPress Tainacan plugin (CVE-2024-7135).

Masteriyo - LMS for WordPress <= 1.6.7 - Sensitive Information Exposure

Zeek plugin detecting CallStranger (CVE-2020-12695) exploitation via UPnP SUBSCRIBE/NOTIFY analysis, identifying DDoS amplification, data…

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

The Joomanager component through 2.0.0 for Joomla! has an Arbitrary File Download issue, resulting in exposing the Credentials of the DataBase.

This is a plugin for the c# R.A.T server providing extension to android based phone systems