
CVE-2026-18718
Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

nameko Arbitrary code execution due to YAML deserialization

Generate malicious files using recently published bidi-attack (CVE-2021-42574)

Original proof-of-concept exploits for React2Shell (CVE-2025-55182), demonstrating remote code execution in Next.js applications via Webpack chunk…

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

Automated scanner and exploit for CVE-2026-27384, an unauthenticated RCE in W3 Total Cache via mfunc/eval() injection. Features auto-detection, 48…

CVE-2025-31324, SAP Exploit

A PoC exploit for CVE-2024-4577 - PHP CGI Argument Injection Remote Code Execution (RCE)

PoC for Acronis Arbitrary File Read - CVE-2022-45451

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload

CVE-2019-17080