
CVE-2026-37072
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php

Proof-of-concept exploit for CVE-2025-32434, a critical RCE in PyTorch's torch.load() that bypasses weights_only=True via memory-mapped file writing.

This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords. The…

Custom BTRFS repair tools for severe extent tree corruption where btrfs check --repair fails (segfault, loop, or deadlock)

CVE-2025-0364: BigAnt Server RCE Exploit

A Python 3 script that uploads a tasks.pickle file that enables RCE in MotionEye. CVE-2021-44255

Spydir is a small utility to monitor file changes in Windows directory regardless of subdirectory and files permissions (exploits CVE-2007-0843)

Proof-of-concept exploit for CVE-2023-33253, enabling authenticated remote code execution in LabCollector 6.0-6.15 via malicious PHP file upload.

X-Ways Acropalypse extension detects CVE-2023-21036 in common images

Proof-of-concept exploit for CVE-2024-21413, a critical Outlook RCE vulnerability that leaks NetNTLMv2 hashes via crafted file:// links, enabling…

A lightweight stdio-based MCP server for local file system operations — read, write, edit, search, exec for AI assistants. Specially optimized for…

Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228

Exploit for Apache Flink CVE-2020-17519 targeting directory traversal vulnerability in versions 1.11.2 and earlier, enabling unauthorized file read…

PoC for CVE-2025-62518 demonstrating tar archive smuggling via tokio-tar PAX header parsing, creating malicious payloads and a vulnerable extractor…

Remote code execution exploit scripts for the WordPress File-Away plugin (CVE-2025-2512 & CVE-2025-2539)

Go-based exploit for CVE-2018-6574 using a shared library (attack.so) to demonstrate remote code execution vulnerability.

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…

Local File Inclusion (LFI) in FHEM 6.0 allows an attacker to include a file, it can lead to sensitive information disclosure.