
wolfCOSE
A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

pluck-CMS-4.7.20-code-injection-vulnerability

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so…

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

Proof-of-concept exploit for CVE-2024-5932, a PHP object injection vulnerability in the GiveWP WordPress plugin, enabling unauthenticated remote code…

The code for personally reproducing the corresponding vulnerability

Detection for CVE-2025-4427 and CVE-2025-4428

WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

CVE-2023-46818 Python3 Exploit for ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability

PoC of CVE-2025-22710

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

GiveWP PHP Object Injection exploit

GiveWP PHP Object Injection exploit

Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)