
CVE-2022-41678
CVE-2022-41678: Dangerous MBeans Accessible via Jolokia API in Apache ActiveMQ

CVE-2022-41678: Dangerous MBeans Accessible via Jolokia API in Apache ActiveMQ

Proof-of-concept for CVE-2025-25279: path traversal in Mattermost Boards allows arbitrary file read via crafted import archive and board duplication.

Rogue-MySql-Server

LOKI (Limited Obstructive Keyboard Impersonator) is a RDP File Transfer Tool Using Keypresses

Bash PoC script exploiting CVE-2019-6447 in ES File Explorer to list files, photos, videos, apps, and download files from vulnerable Android devices.

An input validation vulnerability in Apache Superset allows an authenticated attacker to create a MariaDB connection with local_infile enabled,…

Exploit for CVE-2024-12849, an arbitrary file read vulnerability in WordPress Error Log Viewer plugin. Downloads sensitive files via unauthenticated…

Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

ApacheSKywalking SQLi to Read sensitive file

This binary POC automates the exploitation of CVE-2024-36991 by sending crafted curl requests to a vulnerable Splunk instance. It retrieves sensitive…

WP SuperBackup <= 2.3.3 - Missing Authorization to Unauthenticated Back-Up File Download

Pack up to 3MB of data into a tweetable PNG polyglot file.

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

Exfiltrate files using the HTTP protocol version ("HTTP/1.0" is a 0 and "HTTP/1.1" is a 1)

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

Machine Learning Network Share Password Hunting Toolkit

Proof of concept code to exploit CVE-2020-12116: Unauthenticated arbitrary file read on ManageEngine OpManger.

PoC for CVE-2009-0229 "Print Spooler Read File Vulnerability" LPE AFR (related to CVE-2020-1048)