
CVE-2021-42362
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the…

The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the…

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

CVE-2023-50164 An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a…

POC for CVE-2023-40028: Ghost CMS Arbitrary File Read

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication…

Docker container to setup a vulnerable elfinder version on both nginx and apache servers. Can be used to test vulnerability POC

CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that…

Remote Code Execution for Chamilo LMS

CVE-2018-17246 - Kibana LFI < 6.4.3 & 5.6.13

Unauthenticated Arbitrary File Read via Absolute Path

PoC for CVE-2024-24576 vulnerability "BatBadBut"

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

Proof-of-concept exploit for CVE-2023-5966, an arbitrary file upload vulnerability in EspoCRM 2.7.4 and earlier, enabling remote code execution via a…

Exploit and scanner for CVE-2024-24919, an unauthenticated arbitrary file read in Check Point VPN appliances, enabling sensitive file disclosure and…

A critical security vulnerability, identified as CVE-2023-50164 (CVE: 9.8) was found in Apache Struts, allowing attackers to manipulate file upload…

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute…

Proof of Concept of Libreoffice file exfiltration vulnerability in Big Blue Button