
CVE-2026-1357
Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS…

The Browser Exploitation Framework Project

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP…

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

Unauthenticated arbitrary file read exploit for Jenkins CVE-2024-23897, with HTTPS and CSRF-crumb support to bypass hardened instances.

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

Exploit for CVE-2026-18080, an unauthenticated arbitrary file upload leading to RCE in ERP Complete HR, Accounting & CRM Suite. Includes Python and…

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

Proof-of-concept exploits for CVE-2026-19912, CVE-2026-19913, and CVE-2026-19914, demonstrating file read and remote code execution in Kaltura,…

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing

PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.

Proof-of-concept exploit for CVE-2026-41551, a path traversal vulnerability in Siemens ROS# file_server, demonstrating remote file read via crafted…

Generates a self-submitting HTML trigger page that exploits a reflected HTML injection in WordPress login (CVE-2026-64638) to display a custom…

Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-60093) in camel-azure-storage-datalake, demonstrating arbitrary…