

CVE-2020-15848




PoC for CVE-2025-8110: Authenticated RCE in Gogs via symlink bypass in PutContents API

Proof of concept (POC) for CVE-2026-23489 GLPI "Fields" plugin <= 1.23.2

Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research



cve2024-49740

WBCE CMS 1.6.1 is affected by a cross-site stored scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a payload crafted…

Cockpit CMS 2.7.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

WSO2-2021-1261: Multiple Cross-Site Scripting in WSO2 ESB

WSO2-2021-1260: Deletion of Arbitrary files via Path Traversal in Artifact Name in WSO2 ESB

WSO2-2021-1258: Zip Slip vulnerability in WSO2 ESB

MAL-005: Zip Slip in Add Carbon Applications in WSO2 ESB

RCE-POC-RealEstate CMS