
CVE-2026-58480
CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via…

CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via…

Proof-of-concept exploit for Grafana path traversal vulnerability (CVE-2021-43798) allowing unauthorized file read via directory traversal in plugin…

Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE

Proof-of-concept exploit for CVE-2026-39938: unauthenticated local file inclusion in Cacti <= 1.2.30, enabling arbitrary file read and remote code…

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

CVE-2025-68645 - A Local File Inclusion (LFI) vulnerability in the Webmail Classic UI of Zimbra Collaboration

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

Automating Exploitation of CVE-2022-44268 ImageMagick Arbitrary File Read

Proof-of-concept exploit for CVE-2024-36837, an unauthenticated arbitrary file read vulnerability in Zhilianyun SRM2.0. Includes batch scanning and…

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

Proof-of-concept exploit for CVE-2022-31793 with IP/file-based target scanning, validation mode, and arbitrary file read via HTTP requests.

CVE-2020-5902 scanner for F5 BIG-IP with Shodan host discovery, LFI file reading, and remote command execution capabilities.

Exploit and detection scripts for CVE-2019-11510, enabling unauthenticated remote file reading on Pulse Secure VPN appliances, with IP scanning and…

Exploit for CVE-2020-17519 targeting Apache Flink directory traversal vulnerability. Enables unauthenticated remote file read for security testing…

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

Python-based exploit for CVE-2025-30208 targeting Vite dev server arbitrary file read. Supports single-target detection, custom file paths, system…

Proof-of-concept exploit for Apache HTTP Server 2.4.49 path traversal (CVE-2021-41773) enabling file read and remote code execution via CGI.