
POC
Store vulnerability POC files including CVE-2026-42588 Spring RCE xml payload
Tools for creating and customizing malicious code or instructions to execute after exploitation.

Store vulnerability POC files including CVE-2026-42588 Spring RCE xml payload
The perfect butler for pentesters, bug-bounty hunters and security researchers

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted…

Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

An open-source post-exploitation framework for students, researchers and developers.

CVE-2023-50164 PoC Application & Exploit script

Validates pre-authentication reflected XSS in WordPress, fingerprints vulnerable versions, checks payload reflection and JSONP, and generates…

Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

Proof-of-concept exploiting WordPress pre-auth XSS to RCE via DOM clobbering, REST API abuse, and malicious plugin upload for server-side execution.…


CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

VBScript minifier

Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)