
CVE-2024-45590-PoC
Proof-of-concept exploit for CVE-2024-45590, demonstrating unauthenticated remote code execution in a WordPress plugin via arbitrary file upload.…

Proof-of-concept exploit for CVE-2024-45590, demonstrating unauthenticated remote code execution in a WordPress plugin via arbitrary file upload.…

Remote Command Execution exploit for Rejetto HTTP File Server 2.3.x (CVE-2014-6287) rewritten in Python 3 for modern offensive security testing.

Python-based scanner for CVE-2024-27954, a Local File Inclusion vulnerability in the WordPress wp-automatic plugin. Supports multithreaded scanning,…

PoC exploit for CVE-2019-13086 targeting SQL injection and file upload vulnerabilities in CSZ CMS. Includes experimental setup and reproduction code…

Exploit for CVE-2025-31131, a path traversal vulnerability in YesWiki < 4.5.2, enabling arbitrary file read via the squelette parameter. Includes…

Crawlomatic Multipage Scraper Post Generator <= 2.6.8.1 - Unauthenticated Arbitrary File Upload

The Eventin plugin (<= 4.0.26) for WordPress contains an unauthenticated arbitrary file read vulnerability

Step-by-step walkthrough for exploiting Apache Struts CVE-2024-53677 RCE via file upload manipulation, including OGNL injection, payload embedding,…

Detailed CVE-2021-31856 report with PoC and code analysis for a SQL injection vulnerability in Meshery's pattern file API, enabling unauthenticated…

Proof-of-concept exploit for CVE-2024-51747 enabling authenticated file read and deletion via SQLite database manipulation in a web application's…

Python exploit for CVE-2023-40028 in Ghost CMS, enabling arbitrary file read via symlink abuse in ZIP uploads. Includes automated cleanup.

Automated exploit for CVE-2024-25641 targeting Cacti 1.2.26. Achieves remote code execution via authenticated arbitrary file write in the Package…

Proof-of-concept exploit for CVE-2023-27564 enabling anonymous file read in n8n via path traversal in the REST API. Intended for security research…

Python exploit for CVE-2024-56264, an arbitrary file upload vulnerability in WordPress ACF City Selector plugin <=1.14.0, enabling remote code…

PoC exploit for CVE-2018-18778: arbitrary file read in mini_httpd 1.29 via empty Host header, affecting IoT devices from Huawei, Zyxel, and others.

WordPress ACF City Selector plugin <= 1.14.0 - Arbitrary File Upload vulnerability

FileOrganizer <= 1.0.9 - Authenticated (Subscriber+) Arbitrary File Upload

WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability