
Limelighter
A tool for generating fake code signing certificates or signing real ones

A tool for generating fake code signing certificates or signing real ones

Finding Java/C# gadget chains with CodeQL

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)

CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

CVE-2022-41852 Proof of Concept (unofficial)

CVE-2024-28397: js2py sandbox escape, bypass pyimport restriction.

CVE-2022-22947批量

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

Apache Solr Backup/Restore APIs RCE Poc (CVE-2023-50386)

Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)

RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer

PoC exploit for CVE-2025-48543 in C++