
CVE-2026-18718
Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

ARPrice <= 4.0.3 - Authenticated (Subscriber+) PHP Object Injection

Python exploit for CVE-2018-15133, achieving remote code execution on vulnerable Laravel applications via insecure deserialization of encrypted…

Proof-of-concept exploit for CVE-2026-7393: unrestricted file upload in Pizzafy Ecommerce System 1.0 allowing authenticated administrators to upload…

PoC exploit for CVE-2021-26084, an OGNL injection vulnerability in Atlassian Confluence allowing unauthenticated remote code execution via crafted…

CVE-2022-22947批量

Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer

CVE-2020-26217 XStream RCE POC

Generate malicious files using recently published bidi-attack (CVE-2021-42574)

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

Original proof-of-concept exploits for React2Shell (CVE-2025-55182), demonstrating remote code execution in Next.js applications via Webpack chunk…

phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC (CVE-2009-1151)

CVE-2025-3914-PoC | The Aeropage Sync for Airtable WordPress plugin (≤ v3.2.0) is vulnerable to authenticated arbitrary file uploads due to…

CVE-2021-44228

monstra_cms-3.0.4-上传getshell CVE-2018-17418