
CVE-2026-36669-FengOffice
Detailed security advisory for CVE-2026-36669: unauthenticated arbitrary file upload in Feng Office, enabling stored XSS and session hijacking.…

Detailed security advisory for CVE-2026-36669: unauthenticated arbitrary file upload in Feng Office, enabling stored XSS and session hijacking.…

Proof-of-concept scripts and Docker lab for reproducing CVE-2023-41892, a pre-authenticated remote code execution vulnerability in Craft CMS.…

Exploitation guide and automated detection script for four Vite dev server arbitrary file read vulnerabilities (CVE-2025-30208/31125/31486/32395)…

CVE-2024-1561 - Gradio Arbitrary File Read

File Content Disclosure on Rails Test Case - CVE-2019-5418

This repository contains a Crystallographic Information File (CIF) intended for use on the "Chemistry" machine on Hack The Box (HTB).

Super Forms Unauthenticated File Upload RCE | CVSS 9.8

PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3

Authenticated path traversal and arbitrary file write PoC exploit for Casdoor <3.54.1, enabling RCE via SSH key injection, web shell upload, or…

Proof-of-concept exploit for CVE-2026-48908, an unauthenticated RCE in Joomla SP Page Builder via arbitrary file upload, with adaptive payload…

Unauthenticated OS command injection exploit for GPT-SoVITS Gradio web UI. Delivers RCE via unsanitized path parameters in audio-processing helpers,…

Proof-of-concept exploit for CVE-2026-55168 demonstrating authenticated arbitrary file write via symlink planting during backup restore in Runtipi.

PoC & dokumentasi untuk CVE-2026-7275: Moodle Google Drive Repository (repository_googledocs) — Path Traversal / Arbitrary File Write yang dapat…

Proof-of-concept exploit for authenticated remote code execution in Krayin CRM v2.2.x via unrestricted file upload, supporting web shell and reverse…

Proof-of-concept exploit for CVE-2022-46364, an Apache CXF SSRF vulnerability enabling arbitrary file reads and internal network probing via crafted…

Proof-of-concept exploit for CVE-2024-32258, a path traversal vulnerability in FCEUX NetPlay 2.7.0 enabling unauthenticated remote arbitrary file…

CSV Mass Importer <= 1.2 - Admin+ Arbitrary File Upload

Technical analysis and safety-conscious research harness for CVE-2019-6447 in ES File Explorer for Android