
CVE-2025-28915
Exploit for CVE-2025-28915: WordPress ThemeEgg ToolKit arbitrary file upload vulnerability allowing remote Web Shell deployment. Includes…

Exploit for CVE-2025-28915: WordPress ThemeEgg ToolKit arbitrary file upload vulnerability allowing remote Web Shell deployment. Includes…

Exploit CVE-2024-54262: Arbitrary File Upload in Import Export for WooCommerce

WpDiscuz 7.0.4 Arbitrary File Upload Exploit

Go-based scanner and exploit for CVE-2020-5902, targeting F5 BIG-IP devices. Supports command execution and file reading via HTTP requests, enabling…

Proof-of-concept exploit for CVE-2024-1302 demonstrating unauthenticated log file download in Badgermeter moni:tool, exposing sensitive information…

Python exploit for CVE-2022-24716: arbitrary file disclosure in Icinga Web 2 versions <2.8.6, <2.9.6, <2.10. Usage: python3 exploit.py -u <url> -f…

Python exploit for CVE-2021-46381 targeting D-Link DAP-1620 arbitrary file read vulnerability with FOFA-based device discovery.

My version - Easy File Sharing Web Server 7.2 - 'UserID' - Win 7 'DEP' bypass

Exploit for CVE-2019-3396, a path traversal and RCE vulnerability in Confluence Server, enabling unauthorized file read and remote code execution.

Unauthenticated remote code execution exploit for Payroll Management System v1.0 via malicious file upload, with filename prediction and reverse…

Proof-of-concept exploit for MLflow path traversal (CVE-2023-1177) allowing unauthorized file read via crafted API requests.

Proof-of-concept exploit for CVE-2020-1938 (Ghostcat) targeting Apache Tomcat AJP connector, allowing file read and potential RCE. Includes Docker…

Python exploit for CVE-2024-9935 targeting unauthenticated arbitrary file download in PDF Generator Addon for Elementor Page Builder (<=1.7.5).

Python exploit for ThinkAdmin CVE-2020-25540, enabling unauthorized directory traversal and arbitrary file read via a single URL argument.

Automated Exploit for CVE-2017-9841 (eval-stdin.php vulnerable file)

GPX Viewer <= 2.2.8 - Authenticated (Subscriber+) Arbitrary File Creation

Plugin A/B Image Optimizer <= 3.3 - Authenticated (Subscriber+) Arbitrary File Download

Exploit for ImageMagick CVE-2022-44268, demonstrating arbitrary file read via crafted image. Includes PoC and analysis for security testing.