
CVE-2026-28134
JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution
Custom payload crafting, obfuscation, AV evasion, and delivery mechanism tools.

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

halo cms plugin 1-request rce from a url, PoC + exploit chain

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

In-memory Mach-O dylib loader for stock macOS Python; decrypts, maps, and runs payloads without dlopen or writing to disk, with optional encrypted…

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

Proof-of-concept exploit for CVE-2026-14669, a PostgreSQL to_char() timezone abbreviation heap buffer overflow enabling RCE through information leak…

CVE-2026-43499 (GhostLock) — Linux kernel futex PI rt_mutex UAF ARM32 privilege escalation research targeting Huawei Watch 4 Pro (kernel 5.4.210)

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

Proof-of-concept RCE for Langflow CVE-2026-33017 using a malicious custom component to execute OS commands via build_public_tmp and retrieve output…

Exploits unauthenticated RCE in Apache Gravitino < 1.2.1 via H2 JDBC INIT; hosts SQL/Java payloads, executes commands, and exfiltrates output over…

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

CVE-2026-39154 · Stored XSS in CometChat JS SDK

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit…

PoC exploit for CVE-2022-3218 targeting WiFi Mouse Server 1.7.8.5, achieving RCE via keystroke injection and in-memory PowerShell payload delivery…

PoC for CVE-2025-64512: pdfminer.six CMapDB pickle deserialization RCE via crafted PDF