
CVE-2024-10508
This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific…

This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific…

Docker container lab to play/learn with CVE-2021-41773

A lab demonstration of the log4shell vulnerability: CVE-2021-44228

CVE-2024-0406 POC using symlinks

Proof-of-concept exploit for CVE-2026-37064: unauthenticated user enumeration in Veno File Manager 4.4.9 via crafted POST request to…

An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted…

Tiny File Manager v2.4.7 and below are vulnerable to Cross Site Scripting

Exploit for Apache HTTP Server path traversal and file disclosure vulnerability CVE-2021-42013, enabling unauthorized access to files on vulnerable…

Batch vulnerability scanner for CVE-2026-39363 in Vite dev server, exploiting WebSocket origin validation bypass to read arbitrary files via…

Technical analysis and detection guidance for critical unrestricted file upload in Elementor Pro (CVE-2026-32475) leading to remote code execution.

XSS Vulnerability via File Upload in Ferozo Webmail Application

Proof-of-concept exploit for CVE-2024-27665, demonstrating stored XSS in Unifiedtransform's Syllabus file upload, with reproduction steps.

An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines.

Mitigation/fix of CVE-2021-41773 A Path Traversal And File Disclosure Vulnerability In Apache


Go-based scanner for Apache Tomcat AJP file read/inclusion vulnerability (CVE-2020-1938). Detects and exploits Ghostcat to read arbitrary files or…

Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract…