
CVE-2026-2413
Ally – Web Accessibility & Usability <= 4.0.3 - Unauthenticated SQL Injection via URL Path

Ally – Web Accessibility & Usability <= 4.0.3 - Unauthenticated SQL Injection via URL Path

Exploits Apache HTTP Server CVE-2021-42013 for path traversal and CGI-based remote code execution during penetration testing.

Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…

PoC exploit for CVE-2024-20767 in Adobe ColdFusion, leveraging an improper access control flaw to read arbitrary files from affected servers.

Exploit for CVE-2024-28995 affecting SolarWinds Serv-U 15.4.2 HF 1 and previous versions

Exploit for CVE-2024-4956 affecting all previous Sonatype Nexus Repository 3.x OSS/Pro versions up to and including 3.68.0

Proof-of-concept for stored cross-site scripting in Redaxo's mediapool (CVE-2024-50803), demonstrating malicious SVG upload on versions below 5.18.0…

Proof-of-concept exploit for CVE-2026-59310, demonstrating remote path traversal via crafted syslog messages to write arbitrary log files on VMware…

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

Proof-of-concept exploit for Apache Struts S2-072 (CVE-2026-73633), demonstrating CPU and memory exhaustion by sending crafted JSON requests to the…

Proof-of-concept exploit for FreePBX Endpoint module CVE-2025-5781: chains unauthenticated SQL injection with database manipulation and scheduled…

mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut

Exploit for CVE-2026-64638, a pre-authentication reflected XSS in WordPress login, enabling injection of malicious JavaScript into /wp-login.php…

Python exploit for CVE-2025-70559 targeting an upload directory bypass/remote code execution; run with LHOST and LPORT to establish a reverse shell.

Exploit for CVE-2025-6440: unauthenticated arbitrary file upload in WooCommerce Designer Pro WordPress plugin, enabling RCE via malicious PHP upload.

Bash exploit for CVE-2026-23550 that triggers unauthenticated WordPress admin login via crafted REST API request to Modular Connector's…

Python proof-of-concept exploit for CVE-2026-7458, an unauthenticated authentication bypass in PickPlugins User Verification WordPress plugin via…

Proof-of-concept exploit for CVE-2026-72898 in Metabase, with technical reproduction steps and usage guidance for validating the vulnerability during…