
CVE-2026-4040-Race-Condition-in-File-Upload-Leading-to-RCE
Reproduces CVE-2026-4040: Flask upload server with TOCTOU race condition and exploit script demonstrating arbitrary remote code execution.

Reproduces CVE-2026-4040: Flask upload server with TOCTOU race condition and exploit script demonstrating arbitrary remote code execution.

Python exploit for RCE in Wordpress

Responsive FileManager v.9.9.5 vulnerable to CVE-2022-46604.

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

A stored cross-site scripting (XSS) vulnerability exists in OpenKM version 7.1.40.

Mautic < 5.2.3 Authenticated RCE

This tool is a Proof of Concept (PoC) intended for security research and educational purposes only. Using this tool on systems without explicit…

CVE-2026-45247 - Mirasvit Full Page Cache Warmer for Magento 2 Unauthenticated PHP Object Injection -> Remote Code Execution


Podlove Podcast Publisher Unauthenticated File Upload RCE via is_image() vs extract_file_extension() Mismatch | CVSS 9.8

CVE-2025-24893 tool

CVE-2023-38831 - WinRAR

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

Remote code execution in Mediawiki Score

Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload

Persists BurpSuite proxy history, Repeater requests, and Intruder payloads across sessions; exports and imports .log files for web pentesting context.