
wp2shell
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
mcp-remote exposed to OS command injection



A "Mishandling of Input to API" or "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure…

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)


A PoC exploit for CVE-2020-13945 - Apache APISIX Remote Code Execution (RCE)

Proof-of-concept exploit for CVE-2026-42154, a denial-of-service vulnerability in Prometheus Remote Read endpoint via crafted Snappy-compressed…

Apache APISIX batch-requests RCE(CVE-2022-24112)

Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

.json and .yaml files used to exploit CVE-2018-25031

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…