Wade Guest

2 exploits Active since Feb 2026
CVE-2020-37071 EXPLOITDB CRITICAL python WORKING POC
CraftCMS 3 vCard Plugin 1.0.0 - Code Injection
CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.
CVSS 9.8
EIP-2026-116495 EXPLOITDB python WORKING POC
Virtual VCR Max .0a - '.vcr' Buffer Overflow (PoC)