
cve-2026-64638-banner-poc
Generates a self-submitting HTML trigger page that exploits a reflected HTML injection in WordPress login (CVE-2026-64638) to display a custom…

Generates a self-submitting HTML trigger page that exploits a reflected HTML injection in WordPress login (CVE-2026-64638) to display a custom…

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

Drupal CVE-2024-45440

Go-based scanner for CVE-2019-5418 (Ruby on Rails file disclosure) that reads a list of websites and tests for the vulnerability using a burl-derived…

Automated enumeration and file download tool exploiting CVE-2020-3452 in Cisco ASA devices, with Lua bytecode decompilation support.

eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion

Python PoC for CVE-2022-44268 that embeds arbitrary file contents into PNG images via ImageMagick, with extraction support for exiftool.

The next generation encrypted file sharing project

Proof-of-concept exploit for CVE-2021-29447, a WordPress XXE vulnerability enabling arbitrary file disclosure and SSRF via crafted WAV files.

Demonstrates a path traversal vulnerability in an official eml-parser example script, allowing arbitrary file write via crafted attachment filenames,…

CVE-2025-52691 Scanner - Detects vulnerable SmarterMail installations (CVSS 10.0 RCE)

Exploit for CVE-2026-25732, a path traversal in NiceGUI's FileUpload that allows unauthenticated arbitrary file write. Includes usage examples for…

Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

Decrypts Grafana DataSource passwords by exploiting CVE-2021-43798 directory traversal to retrieve configuration files and derive encryption keys.

Exploit tool for Apache Tomcat CVE-2020-1938 LFI vulnerability, enabling sensitive file reading and remote JSP payload execution via AJP connector.

Proof-of-concept exploit for CVE-2024-34470: unauthenticated path traversal in HSC Mailinspector's /public/loader.php, enabling arbitrary file read…

RCE exploit for dompdf