
CVE-2024-41453_CVE-2024-41454
Proof-of-concept exploits for CVE-2024-41453 and CVE-2024-41454 demonstrating stored XSS and malicious file upload vulnerabilities in ProcessMaker 4…

Proof-of-concept exploits for CVE-2024-41453 and CVE-2024-41454 demonstrating stored XSS and malicious file upload vulnerabilities in ProcessMaker 4…

PoC and exploit for CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with Docker setup and curl-based exploitation commands for file…

Docker-based lab environment for exploiting Tomcat CVE-2017-12615 arbitrary file write via PUT method, with bypass techniques and proof-of-concept…

Educational lab demonstrating CVE-2017-8291 (PIL/GhostScript RCE) via crafted EPS file upload with PNG extension, including Docker setup and PoC…

Python exploit and checker script for CVE-2024-3400 Palo Alto Command Injection and Arbitrary File Creation

Proof-of-concept exploit for CVE-2023-31716, a Local File Inclusion vulnerability in FUXA SCADA/HMI software versions <= 1.1.12, enabling arbitrary…

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

Crafthemes Demo Import <= 3.3 - Authenticated ( Admin+) Arbitrary File Upload in process_uploaded_files

CTF wargame platform featuring Unicode bypass exploitation (CVE-2015-9238), flag file segmentation, brute force delay, and password hashing for…

YISF 2024 CTF-Web (Directory Traversal via ".tar" file, CVE-2007-4559), easy

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…

Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-60093) in camel-azure-storage-datalake, demonstrating arbitrary…

Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-66906) in camel-azure-storage-blob, demonstrating arbitrary file…

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS…

Technical audit and reproduction of CVE-2026-21858, an n8n RCE chain exploiting Content-Type confusion for arbitrary file read, session forgery, and…

Proof-of-concept exploit for CVE-2026-21440, a critical path traversal in AdonisJS multipart uploads enabling arbitrary file write and remote code…

Proof-of-concept exploit for CVE-2025-11371, a local file inclusion vulnerability in Gladinet CentreStack/Triofox, demonstrating unauthorized file…

Proof-of-concept exploit for CVE-2025-11371, an unauthenticated Local File Inclusion in Gladinet CentreStack and TrioFox, enabling remote file…