
CVE-2026-66491
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2

Generates a PDF with embedded JavaScript to demonstrate CVE-2026-21013, an OpenAction injection leading to script execution in vulnerable PDF readers.

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4

Proof-of-concept exploit for CVE-2026-11784, a CSRF vulnerability in the Optimole WordPress plugin allowing arbitrary file overwrite via missing…

Python exploit for CVE-2006-3392, a path traversal in Webmin/Usermin allowing arbitrary file read, demonstrated by retrieving /etc/shadow.

Arbitrary file read controller based on CVE-2021-29447

Lightweight Python script to check Icecast servers for CVE-2018-18820 vulnerability, requiring only the requests library for automated detection.

Proof-of-concept exploit for CVE-2025-11988, demonstrating unauthenticated arbitrary JSON file deletion in WordPress Crypto plugin via crafted AJAX…

CVE-2020-25213 Wordpress File Manager 6.7 Plugin 0day exploit

Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

Proof-of-concept exploit for CVE-2022-41401, a server-side request forgery (SSRF) vulnerability in OpenRefine <= v3.5.2, enabling unauthorized…

WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability

Unrestricted File Upload DoS Vulnerability discovered in MediaCrush thru 1.0.1(CVE-2025-61506)

Proof-of-concept exploit for Apache HTTP Server path traversal vulnerability (CVE-2021-41773) enabling file disclosure and source code leakage…

CVE‑2025‑3515 — Drag and Drop Multiple File Upload for Contact Form 7

Lightweight Python script to detect CVE-2017-9798 in shared hosting environments by scanning for vulnerable .htaccess files, exiting with code 1 if…

Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10

Exploit for CVE-2006-3392: unauthenticated local file inclusion in Webmin before 1.290 and Usermin before 1.220, bypassing path traversal filters…