
CVE-2026-84645
Jenkins PersistenceRoot Deserialization RCE (SECURITY-3972) — PoC & analysis. Requires Item/Configure; affects weekly <= 2.579 / LTS <= 2.568.2

Jenkins PersistenceRoot Deserialization RCE (SECURITY-3972) — PoC & analysis. Requires Item/Configure; affects weekly <= 2.579 / LTS <= 2.568.2

CVE-2026-76060 PoC for a ZoneMinder vulnerability leading to RCE

Proof-of-concept for CVE-2025-60787, demonstrating remote code execution in MotionEye <= 0.43.1b4 via client-side validation bypass and command…

Proof-of-concept exploit for CVE-2026-19626, an authenticated remote code execution in SecurityCenter report generation, demonstrating a non-admin…


To reproduce CVE-2021-31630

CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Proof-of-concept exploit for CVE-2023-49314 demonstrating code injection in Asana Desktop on macOS via Electron Fuses, with automated vulnerability…

CVE-2025-53652: Jenkins Git Parameter Analysis

CVE-2022-1292 OpenSSL c_rehash Vulnerability

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Proof-of-concept exploit for CVE-2025-51482, demonstrating remote code execution via unsafe exec() usage and sandbox bypass in the Letta AI agent…

CImg Library v.2.3.3 - command injection

Details about the Blind RCE issue(SPX-GC) in SPX-GC

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…

Automatic SSTI detection tool with interactive interface

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.