
CVE-2022-2414-POC
Proof-of-concept exploit for CVE-2022-2414, an XML external entity (XXE) vulnerability in FreeIPA, enabling remote file retrieval via crafted HTTP…

Proof-of-concept exploit for CVE-2022-2414, an XML external entity (XXE) vulnerability in FreeIPA, enabling remote file retrieval via crafted HTTP…

Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.10.1321 - Cross-Site Request Forgery to…

PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

CLI scanner for CVE-2020-17453 that tests single or multiple URLs for the vulnerability, designed for bug bounty hunters and penetration testers.

Isolated lab research writeup for VMware vCenter Server CVE-2021-21972, covering unauthenticated arbitrary file upload to RCE, Nmap-based detection,…

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

Python proof-of-concept for CVE-2022-1386, an unauthenticated SSRF in Fusion Builder WordPress plugin, demonstrating file read via crafted HTTP…

This is POC for CVE-2024-2667 (InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload)

CVE-2021-46078 - An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can…

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

A penetration testing tool for finding file upload bugs (NDSS 2020)

Apache HTTPd (2.4.49) – Local File Disclosure (LFI)

Poc for CVE-2023-23752 (joomla CMS)

CVE-2021-46078 - An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can…

The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is…

WordPress File Upload RCE Exploit

WordPress WP Time Capsule Plugin Arbitrary File Upload Vulnerability