
CVE-2023-46818
CVE-2023-46818 Python3 Exploit for ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability

CVE-2023-46818 Python3 Exploit for ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability

(Wordpress) Ninja Forms File Uploads Extension <= 3.0.22 – Unauthenticated Arbitrary File Upload

Basic code for creating the Alibaba FastJson + Spring gadget chain, as used to exploit Apache Dubbo in CVE-2019-17564 - more information available at…

Generate malicious files using recently published bidi-attack (CVE-2021-42574)

PoC exploit for CVE-2021-26084, an OGNL injection vulnerability in Atlassian Confluence allowing unauthenticated remote code execution via crafted…

phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC (CVE-2009-1151)

SnakeYAML-CVE-2022-1471-POC

CVE-2025-64512: pdfminer.six pickle deserialization rce; .pickle.gz + pdf generator w/ custom payloads

CVE-2021-3129-Laravel Debug mode

CVE-2024-0195 Improper Control of Generation of Code ('Code Injection')

CVE-2020-26217 && XStream RCE

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

[CVE-2020-0688] Microsoft Exchange Server Fixed Cryptographic Key Remote Code Execution (RCE)

Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload

CVE-2020-26217 XStream RCE POC

Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-0740)

Proof-of-concept exploit for CVE-2022-42899, demonstrating remote code execution in Apache Commons Text 1.5-1.9 via StringSubstitutor interpolation…

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall