
CVE-2023-34836
A Reflected Cross-Site Scripting (XSS) vulnerability exists in Microworld Technologies eScan Management Console v14.0.1400.2281. The vulnerable…

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Microworld Technologies eScan Management Console v14.0.1400.2281. The vulnerable…

Exploit-WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read

Python exploit class for CVE-2025-58360, an XXE vulnerability in GeoServer's GetMap function enabling arbitrary file read. Includes automated…

Proof‑of‑concept for CVE‑2024‑58258, a SugarCRM (<13.0.4 / <14.0.1) flaw where user input is parsed as LESS in /css/preview, allowing unauthenticated…

Proof-of-concept exploit for CVE-2024-9234, an unauthenticated arbitrary file upload vulnerability in GutenKit <= 2.1.0. Includes a Python script for…

Command-line exploit script for CVE-2024-24919 path traversal vulnerability in Check Point Security Gateway, enabling unauthorized file access…

(CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution

Python exploit for Chamilo Unrestricted File Upload Vuln - CVE-2023-4220

Python exploit for CVE-2023-40028 enabling authenticated arbitrary file read on Ghost CMS, designed for educational use and HTB machines.

Documentation of CVE-2025-65790: Reflected XSS vulnerability in FuguHub 8.1 via unsanitized SVG rendering in the file manager interface, with PoC and…

Educational exploit for CVE-2022-46604 directory traversal in Responsive File Manager v9.13.4. Includes a modified Python script with automatic…

HUSKY – Products Filter Professional for WooCommerce < 1.3.6.6 - Local File Inclusion PoC

Proof-of-Concept (PoC) exploit script for the Directory Traversal vulnerability (CVE-2016-10924) found in the WordPress plugin ebook-download…

Proof-of-concept exploit for CVE-2025-49131, a sandbox escape in FastGPT allowing arbitrary file read/write, import bypass, and remote code execution…

Proof-of-concept exploit for CVE-2020-3452, a path traversal in Cisco ASA/FTD, enabling unauthenticated file disclosure. Automates extraction of…

Authenticated arbitrary file read exploit for the File Away WordPress plugin (CVE-2025-2539). Includes PoC, attack flow, detection signatures, and…

Proof-of-concept exploit for CVE-2023-31059, an unauthenticated path traversal in Repetier-Server ≤1.4.10, enabling arbitrary file read via crafted…

PoC exploit for CVE-2024-46987 — Camaleon CMS arbitrary path traversal (file read)