
-CVE-2026-1657
Exploit for CVE-2026-1657, an unauthenticated image upload vulnerability via the 'ep_upload_file_media' AJAX endpoint, allowing remote file upload.

Exploit for CVE-2026-1657, an unauthenticated image upload vulnerability via the 'ep_upload_file_media' AJAX endpoint, allowing remote file upload.

Proof-of-concept exploit for CVE-2026-23745, a path traversal vulnerability in node-tar allowing arbitrary file overwrite via malicious tar archives.

Authenticated PoC for CVE-2026-0911: tests weak file upload and orphan file behavior in WordPress Hustle plugin's module import endpoint, with…

Technical write-up and proof-of-concept for CVE-2023-46474, a remote code execution vulnerability in PMB <=7.5.3 via unrestricted file upload,…

Exploit for CVE-2026-39363, a Vite Dev Server WebSocket arbitrary file read vulnerability, with Python and Node.js scripts for automated exploitation…

The Browser Exploitation Framework Project

Detection for CVE-2025-61675, CVE-2025-61678 & CVE-2025-66039

Cryptographically verifiable web archiving. Playwright capture → SHA-256 Merkle hash → Bitcoin-anchored OpenTimestamps → permanent Arweave storage.

PanaceaSoft [all products] 0day exploit

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

Proof-of-concept and GLSL fuzzer for CVE-2026-9999 in Chrome's ANGLE/Metal WebGL backend, with build fingerprinting, curated shaders, and crash…

PoC for CVE-2025-8110: Authenticated RCE in Gogs via symlink bypass in PutContents API

CVE-2026-64638 (XSS2shell) POC.

Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload [POC & Xploit]

CVE-2025-68645

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型…