
CVE-2026-44402
Exploit for CVE-2026-44402 targeting Voltronic Power SNMP Web Pro 1.1, enabling unauthenticated remote code execution via malicious firmware upload.…

Exploit for CVE-2026-44402 targeting Voltronic Power SNMP Web Pro 1.1, enabling unauthenticated remote code execution via malicious firmware upload.…

Reproduction environment and proof-of-concept for Spring Cloud Function SpEL injection leading to remote code execution, with a runnable Java 11 demo…

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

Magento ver. 2.4.6 - XSLT Server Side Injection

Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution

GitLab 11.4.7 SSRF配合redis远程执行代码

PoC exploit for a CSRF vulnerability in Apache Roller v6.1.2 profile update endpoint. Includes HTML form exploit code to demonstrate unauthorized…

CVE-2025-54100(PowerShell 远程代码执行漏洞)

WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型…

Exploits CVE-2016-10924 file disclosure in WordPress eBook Download plugin to brute-force server processes and retrieve sensitive files.

CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file…

Proof-of-concept exploit for CVE-2025-63708, a stored XSS vulnerability in AI Font Matcher. Demonstrates session cookie theft via unsanitized font…

WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability

ScottCart <= 1.1 - Unauthenticated Remote Code Execution

PoC for the ThemeBleed Windows 11 CVE-2023-38146 written in python using impacket. https://jnns.de/posts/cve-2023-38146-poc/

ChurchInfo 1.2.13-1.3.0 Remote Code Execution Exploit