
slippy-book-exploit
CVE-2023-44451, CVE-2023-52076: RCE Vulnerability affected popular Linux Distros including Mint, Kali, Parrot, Manjaro etc. EPUB File Parsing…

CVE-2023-44451, CVE-2023-52076: RCE Vulnerability affected popular Linux Distros including Mint, Kali, Parrot, Manjaro etc. EPUB File Parsing…

WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload

CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC

Python exploit for CVE-2022-36804, enabling remote command execution and file transfer on vulnerable Bitbucket Server/Data Center via crafted archive…

Proof-of-concept exploit for CVE-2026-25964, an authenticated local file disclosure in Tandoor Recipes via path traversal in recipe import, allowing…

Demonstrates CVE-2026-31431 by poisoning the cache for a target file with attacker-controlled payload bytes, illustrating a web cache poisoning…

Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)

Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…

Exploit for CVE-2026-1657, an unauthenticated image upload vulnerability via the 'ep_upload_file_media' AJAX endpoint, allowing remote file upload.

Exploit by Chirag Artani for CVE-2024-11613 in WordPress File Upload

Proof-of-concept exploit for Apache PDFBox path traversal vulnerability (CVE-2026-23907), demonstrating arbitrary file write via malicious PDFs with…

Proof-of-concept exploit for CVE-2026-41551, a path traversal vulnerability in Siemens ROS# file_server, demonstrating remote file read via crafted…

Automated exploit for CVE-2026-22241, an unrestricted file upload vulnerability in Open eClass, enabling remote code execution via a webshell with…

Detailed analysis and proof-of-concept for CVE-2020-13671, a Drupal core remote code execution vulnerability via file upload, including root cause,…

Exploit and proof-of-concept for arbitrary file deletion in Perfmatters WordPress plugin (CVE-2026-4350), with Python exploit and bash POC scripts…

Exploit for CVE-2026-21858, a critical unauthenticated content-type parsing flaw in n8n allowing arbitrary file read, credential theft, and remote…

Authenticated PoC for CVE-2026-0911: tests weak file upload and orphan file behavior in WordPress Hustle plugin's module import endpoint, with…

Technical write-up and proof-of-concept for CVE-2023-46474, a remote code execution vulnerability in PMB <=7.5.3 via unrestricted file upload,…