
CVE-2026-61424
DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

Proof-of-concept exploit for CVE-2026-37071: arbitrary file rename in Veno File Manager 4.4.9 enabling privilege escalation to super administrator…

Perforce security research and tools - CVE-2026-6043

CVE-2021-46075 - A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access…

CVE-2021-46075 - A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access…

CVE-2026-0827 PoC

Exploit and analysis for CVE-2026-5465, an IDOR in Amelia WordPress plugin allowing authenticated Provider role to escalate privileges and achieve…

Proof-of-concept exploit for a mass assignment privilege escalation vulnerability in Camaleon CMS < 2.9.1. Authenticated low-privilege users can…

CVE-2025-60375 — Authentication bypass / incorrect access control in PerfexCRM < 3.3.1 (admin login)

Proof-of-concept for CVE-2025-57392 demonstrating insecure default file permissions in BenimPOS Desktop V3.0, enabling privilege escalation via…

Local Privilege Escalation vai `below` (CVE-2025-27591) - PoC Exploit

CVE-2025-52216 – Cooler Master MasterCTRL Silent Installation of Insecure Services

HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update

PoC of CVE-2025-46203

Simple Dashboard <= 2.0 - Unauthenticated Privilege Escalation

Proof-of-concept demonstrating incorrect access control in Unifiedtransform v2.0, allowing students to modify exam rules via the /exams/edit-rule…

Proof-of-concept exploit for CVE-2025-25614, an incorrect access control vulnerability in Unifiedtransform v2.0 allowing teachers to modify fellow…

Eyewear prescription form <= 4.0.18 - Missing Authorization to Unauthenticated Arbitrary Options Update