
CVE-2022-24716
Exploit for CVE-2022-24716 in Icinga Web 2, allowing unauthenticated file disclosure of configuration files containing database credentials.

Exploit for CVE-2022-24716 in Icinga Web 2, allowing unauthenticated file disclosure of configuration files containing database credentials.

Patch for CVE-2024-10449: replaces vulnerable loginAction.php with a hardened version that requires database configuration for secure authentication.

Proof of concept for unauthenticated sensitive data disclosure affecting the wp-import-export WordPress plugin (CVE-2022-0236)

A checker (site and tool) for CVE-2014-0160

Subdomain takeover vulnerability checker

WPBF - a multithreaded WP brute forcer

Proof-of-concept for CVE-2024-22641: ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted SVG files, demonstrating regex backtrack limit…

Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)

ZIP File Raider - Burp Extension for ZIP File Payload Testing

Exploit for CVE-2020-3452 targeting a path traversal vulnerability in Cisco devices, enabling unauthorized file read and potential remote code…

CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

Proof-of-concept exploit for CVE-2015-3337 enabling arbitrary file read on ElasticSearch servers via path traversal in the head plugin.

POC for CVE-2021-34429 - Eclipse Jetty 11.0.5 Sensitive File Disclosure

Proof-of-Concept script for WordPress plugin Bit File Manager version 6.0 - 6.5.5 Unauthenticated Remote Code Execution via Race Condition…

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

Proof-of-concept exploit for UniFi OS CVE-2026-34910 auth bypass enabling command injection/RCE, and CVE-2026-34909 path traversal for arbitrary file…

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

Automated RCE exploit for Joomla JCE (CVE-2026-48907) with interactive shell, batch command execution, file download, and proxy support for…