
cve-2024-23897-jenkins-poc
Self-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.

Self-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.

Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin SSRF because…

CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe…

Super Forms Unauthenticated File Upload RCE | CVSS 9.8

CVE-2018-18778 - ACME mini_httpd Arbitrary File Read

Proof-of-concept exploit for CVE-2021-29447, an XXE injection vulnerability in WordPress 5.6–5.7 via malicious WAV file upload, enabling arbitrary…

SourceCodester Online Eyewear Shop Remote File Inclusion Vulnerability

Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

Unauthenticated Arbitrary File Upload in EventPrime Plugin

CVE-2026-27621 - TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload

Documentation of CVE-2025-65790: Reflected XSS vulnerability in FuguHub 8.1 via unsanitized SVG rendering in the file manager interface, with PoC and…

Explore CVE-2022-41741 with the Evil MP4 repository. It offers educational PoCs,and documentation on securing nginx against MP4 file vulnerabilities.…

Detailed disclosure of a stored XSS vulnerability in VaahCMS via unsafe SVG file upload handling, including exploitation flow, affected endpoints,…

Detection rules and YARA/KQL signatures for CVE-2025-60787, an unauthenticated RCE in motionEye via config injection, with process execution and file…

Detailed analysis of CVE-2025-61686, a path traversal vulnerability in React Router's file session storage, including root cause, attack scenarios,…

Lightweight Java 8 web framework for building REST APIs and web applications, with built-in routing, static file serving, and template engine support.

Lightweight Java 8 web framework with routing, filters, and static file serving. Includes security advisory for older versions and CRUD API examples.