
CVE-2025-1307
Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload

Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload

Laboratory validation of CVE-2026-48282 in Adobe ColdFusion RDS with arbitrary CFM file write, code execution, auditd/PCAP evidence, event timeline…

Popcorn HTB write-up covering advanced directory fuzzing, file upload bypass via magic numbers/extension spoofing using Burp Suite, and privilege…

PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)

WordPress Simple File List Unauthenticated RCE Exploit

Unauthenticated Arbitrary File Read exploit for WordPress File Away Plugin ≤ 3.9.9.0.1

Detailed disclosure of CVE-2025-47423: Local File Inclusion in Personal Weather Station Dashboard 12_lts. Includes PoC, vulnerable code analysis, and…

CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

Unauthenticated Local File Inclusion

WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability

Proof-of-concept exploit for CVE-2024-7703, a Stored XSS vulnerability in the ARMember WordPress plugin via malicious SVG file uploads by…

CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vulnerability

Proof-of-concept exploit for CVE-2025-4720, a path traversal vulnerability in SourceCodester SRMS 1.0 allowing arbitrary file deletion via the…

Proof-of-concept exploit for CVE-2025-25279, a Mattermost Focalboard path traversal enabling authenticated arbitrary file read and exfiltration of…

Proof-of-concept exploit for CVE-2021-29447, an XXE injection vulnerability in WordPress 5.6–5.7 via malicious WAV file upload, enabling arbitrary…

SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.

Authenticated remote code execution exploit for m1k1o's Blog v1.3 via unvalidated file upload, with webshell deployment and reverse shell…

A fully refactored, Python 3 compatible exploit script for Tomcat Ghostcat (CVE-2020-1938 / CNVD-2020-10487) AJP Local File Inclusion