> For the complete documentation index, see [llms.txt](https://www.verylazytech.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.verylazytech.com/vulnerabilities-and-exploits.md).

# 🛡️ Vulnerabilities and Exploits

- [CVE - POC](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc.md)
- [Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-23692.md)
- [POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2024-4956-nexus-repository-manager-3-unauthenticated-path-traversal.md)
- [POC - CVE-2024-45241: Path Traversal in CentralSquare's CryWolf](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2024-45241-path-traversal-in-centralsquares-crywolf.md)
- [Telerik Auth Bypass CVE-2024-4358](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/telerik-auth-bypass-cve-2024-4358.md)
- [Check Point Security Gateways Information Disclosure - CVE-2024-24919](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/check-point-security-gateways-information-disclosure-cve-2024-24919.md)
- [CVE-2024-23897 - Jenkins File Read Vulnerability](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-23897-jenkins-file-read-vulnerability.md)
- [CVE-2024–10914- Command Injection Vulnerability in name parameter for D-Link NAS](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-10914-command-injection-vulnerability-in-name-parameter-for-d-link-nas.md): POC - CVE-2024–10914 - Command Injection Vulnerability in name parameter for D-Link NAS
- [POC - CVE-2024-21534 Jsonpath-plus vulnerable to Remote Code Execution (RCE)](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2024-21534-jsonpath-plus-vulnerable-to-remote-code-execution-rce.md): POC - CVE-2024-21534 Jsonpath-plus vulnerable to Remote Code Execution (RCE) due to improper input sanitization
- [CVE-2024-9935 - PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Arbitrary](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-9935-pdf-generator-addon-for-elementor-page-builder-less-than-1.7.5-unauthenticated-arbitra.md): POC - CVE-2024-9935 - PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Arbitrary
- [CVE-2024-50623- Cleo Unrestricted file upload and download](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2024-50623-cleo-unrestricted-file-upload-and-download.md)
- [POC - WordPress File Upload plugin, in the wfu\_file\_downloader.php file before version <= 4.24.11](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-wordpress-file-upload-plugin-in-the-wfu_file_downloader.php-file-before-version-less-than-4.24.1.md): WordPress File Upload plugin, in the wfu\_file\_downloader.php file before version <= 4.24.11
- [POC - Remote and unauthenticated attacker can send crafted HTTP requests to RCE - cve-2025-3248](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-remote-and-unauthenticated-attacker-can-send-crafted-http-requests-to-rce-cve-2025-3248.md)
- [POC - CVE-2025–2539 File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2025-2539-file-away-less-than-3.9.9.0.1-missing-authorization-to-unauthenticated-arbitrary-f.md)
- [POC - CVE-2025-29306 FOXCMS /images/index.html Code Execution Vulnerability](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/poc-cve-2025-29306-foxcms-images-index.html-code-execution-vulnerability.md)
- [CVE-2025–64446 — A Red Team Offensive Playbook for FortiWeb RCE via Path Traversal + Authentication](https://www.verylazytech.com/vulnerabilities-and-exploits/cve-poc/cve-2025-64446-a-red-team-offensive-playbook-for-fortiweb-rce-via-path-traversal-+-authentication.md)
