
CVE-2024-49699
ARPrice <= 4.0.3 - Authenticated (Subscriber+) PHP Object Injection

ARPrice <= 4.0.3 - Authenticated (Subscriber+) PHP Object Injection

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

AR For Woocommerce <= 6.2 - Unauthenticated Arbitrary File Upload

Wordpress - Motors Plugin <= 1.4.64 - Arbitrary Plugin Installation Vulnerability

Exploiting a Reflected Cross-Site Scripting (XSS) attack to create a privileged user through the Webmin's add users feature then getting a reverse…

Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523

PoC for CVE-2023-4220 - Chamilo LMS - Unauthenticated File Upload in BigUpload

[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing

Tatsu Plugin ZIP File add_custom_font unrestricted upload

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.

Exploits CuteNews 2.1.2 via poor file upload checks used when uploading an avatar image leading to RCE.

Animation Addons for Elementor Pro <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload

Proof-of-concept exploit for CVE-2022-34919, demonstrating unauthenticated arbitrary file upload and RCE in Contensis CMS Classic interface via…

Generates reverse shell payloads targeting the GitLab-shell vulnerability CVE-2024-32002 for exploitation testing.

Just small script to exploit CVE-2024-32002

An automated PoC for CVE 2018-15133