
CVE-2026-52886
Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)

Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)
POC for CVE-2026-7720 - Ollama tensor digest path traversal

Easy and fast file sharing from the command-line.

Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!

Encrypted command-and-control tunnel over DNS protocol. Creates stealthy C&C channels for penetration testing, with file transfer, shell access, and…

Serverless, peer-to-peer, local file sharing through sound

ES File Explorer Open Port Vulnerability - CVE-2019-6447

Embed a payload inside a PNG file

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

Tiny payload for transfer via LOKI - Provides high speed Virtual Channel two way file transfer capabilities

Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB

Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the…

Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0

Exploiting Android Vulnerability in ES File Explorer

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Python exploit for CVE-2019-6447 enabling arbitrary file read on ES File Explorer 4.1.9.7.4 for Android. Demonstrates mobile vulnerability…

Proof-of-concept exploit for CVE-2024-51747 enabling authenticated file read and deletion via SQLite database manipulation in a web application's…