
CVE-2024-4040-SSTI-LFI-PoC
CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Proof-of-concept exploit for CVE-2024-22514 enabling remote code execution in iSpyConnect Agent DVR 5.1.6.0 via malicious objects.xml file…

A vulnerability scanner that detects CVE-2021-21980 vulnerabilities.

Exploits CVE-2024-51793 unauthenticated arbitrary file upload in WordPress Computer Repair Shop plugin, scans target lists, uploads PHP webshells,…

Proof-of-concept exploit for CVE-2024-22515, demonstrating arbitrary file upload and remote code execution in Agent DVR 5.1.6.0 via unverified sound…

Proof-of-concept checker for CVE-2025-10951, an unauthenticated path traversal in ml-logger, validating arbitrary file read via /glob and /stream…

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…

Proof-of-concept exploit for CVE-2022-31793 with IP/file-based target scanning, validation mode, and arbitrary file read via HTTP requests.

Proof-of-concept exploit for CVE-2026-37748, an unrestricted file upload vulnerability in Visitor Management System 1.0 leading to remote code…

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…

Shell-based exploit for CVE-2021-41773 targeting Apache HTTP Server path traversal vulnerability, enabling unauthenticated remote file disclosure and…

Exploit toolkit CVE-2017-8759 - v1.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test…

VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.

Atlassian Jira unauthen template injection

Proof-of-concept exploit for CVE-2025-4720, a path traversal vulnerability in SourceCodester SRMS 1.0 allowing arbitrary file deletion via the…

In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a…

CVE-2018-17246 - Kibana LFI < 6.4.3 & 5.6.13

Demo project how to bypass the disable_functions security control of PHP on Linux