
CVE-2024-12877
GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

ARPrice <= 4.0.3 - Authenticated (Subscriber+) PHP Object Injection

Python exploit for CVE-2018-15133, achieving remote code execution on vulnerable Laravel applications via insecure deserialization of encrypted…

Proof-of-concept exploit for CVE-2026-7393: unrestricted file upload in Pizzafy Ecommerce System 1.0 allowing authenticated administrators to upload…

PoC exploit for CVE-2021-26084, an OGNL injection vulnerability in Atlassian Confluence allowing unauthenticated remote code execution via crafted…

Batch vulnerability scanner and exploit tool for CVE-2022-22947 Spring Cloud Gateway RCE, supporting single-target and mass scanning with SpEL…

Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer

Proof-of-concept exploit for CVE-2020-26217, demonstrating remote code execution via deserialization in XStream with a crafted XML payload.

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

nameko Arbitrary code execution due to YAML deserialization

Encode and decode source code files using Unicode bidi control characters to exploit CVE-2021-42574, enabling invisible injection of malicious logic…

[PoC] Privilege escalation & code execution via LFI in PwnDoC

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied

phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC (CVE-2009-1151)

CVE-2025-3914-PoC | The Aeropage Sync for Airtable WordPress plugin (≤ v3.2.0) is vulnerable to authenticated arbitrary file uploads due to…

Exploit tool for CVE-2021-44228 (Log4Shell) with LDAP/JNDI injection server, payload generation, and single-target exploitation script for testing…