
CVE-2013-1081
Novell ZENworks Mobile Management - LFI RCE

Novell ZENworks Mobile Management - LFI RCE

Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters

Metasploit module for CVE-2018-4878

Exploit for CVE-2024-28995

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

CVE-2022-44268 PoC

Proof of Concept for the CVE-2023-47400

Path Traversal Vulnerability in NitroShare v0.3.4

A totally unauthenticated file-upload endpoint in Visual Composer lets anyone drop arbitrary files (e.g., a JSP web-shell) onto the server.

WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型…

Proof-of-concept exploit for CVE-2022-0848 enabling remote code execution in part-db 0.5.11 via a simple bash script.


Complete CosmicSting (CVE-2024-34102) exploit suite for Magento/Adobe Commerce XXE vulnerability

CVE-2022-46364 Apache CXF XOP:Include SSRF / LFI

📂 Grafana LFI Exploit (CVE-2021-43798). Extracción automatizada de credenciales y configuración. 🕵️

Auto exploit RCE CVE-2020-5902

Test and Exploit Scripts for CVE 2022-1388 (F5 Big-IP)

WordPress JSmol2WP Plugin 1.07版本中存在安全漏洞。攻击者可利用该漏洞读取任意文件。