
CVE-2026-0766
Proof-of-concept exploit for CVE-2026-0766, a remote code execution vulnerability in OpenWebUI via tool code injection. Includes command execution,…

Proof-of-concept exploit for CVE-2026-0766, a remote code execution vulnerability in OpenWebUI via tool code injection. Includes command execution,…

Educational examples porting Linux kernel vulnerabilities to Rust, featuring intentionally vulnerable code and exploits for learning kernel security…

对CVE-2021-29505进行复现,并分析学了下Xstream反序列化过程

First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).

Spring Framework RCE exploit (CVE-2022-22965) with analysis code and educational walkthrough for understanding the vulnerability and exploitation…

Step-by-step analysis and exploitation guide for CVE-2019-3396, a critical SSTI vulnerability in Confluence Server & Data Center, including debugging…

Educational proof-of-concept demonstrating SQL injection via dynamic aliases in Django's annotate() and alias() methods (CVE-2025-57833). Includes…

PoC for CVE-2026-12191


Step-by-step analysis and exploitation lab for Drupal CVE-2018-7600 remote code execution vulnerability, including debugging, exploit code, and…

Step-by-step technical analysis of CVE-2019-1698, a WordPress plugin SQL injection vulnerability, with code diff review, vulnerable function…

Educational exploit demo for CVE-2018-1263 (phpMyAdmin RCE/LFI). Includes vulnerable environment setup via Docker and step-by-step attack walkthrough…

In-depth technical analysis of CVE-2021-22204 (ExifTool RCE) with PoC reproduction, payload construction, and Perl code review of the vulnerable DjVu…

In-depth technical analysis of CVE-2021-25804, a VLC AVI parser vulnerability. Includes root cause, patch diff, and exploitation primitives for…

Proof-of-Concept exploit for Apache Struts S2-052 (CVE-2017-9805) XML Deserialization Remote Code Execution. Created while solving the INE eWPTX…

Educational exploit demonstration for CVE-2021-26814 targeting Wazuh v4.0.3, with step-by-step exploitation and remediation code for university-level…

Reproducer for CVE-2026-46590: Apache Camel camel-pqc key-lifecycle unsafe deserialization (FileBasedKeyLifecycleManager legacy .key migration via…

Reproducer for CVE-2026-43865 — Apache Camel camel-hazelcast default-configured instance unsafe Java deserialization (RCE)