
CVE-2026-13157
Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

SCM Manager XSS

Exploit for CVE-2021-44529, a code injection vulnerability in Ivanti EPM Cloud Service Appliance allowing unauthenticated arbitrary code execution as…

Reproducer for CVE-2026-46591: Apache Camel camel-neo4j Cypher injection via property names in CamelNeo4jMatchProperties, enabling authorization…

CVE-2026-9691: Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 Unauthenticated PHP Object Injection PoC,…

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote…

Frontend File Manager Plugin (WordPress) <= 23.6 - Unauthenticated Arbitrary File Deletion to RCE

Proof-of-concept exploit script for CVE-2022-36532 enabling authenticated remote code execution via file upload in Bolt CMS 5.1.12 and below.

Proof-of-concept exploit for Jenkins CVE-2017-1000353, a remote code execution vulnerability via unsafe deserialization in the CLI interface.


PoC of CVE-2025-22783

Multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department in Customer Support System 1.0 allow authenticated…

A PHP CVE-2025-1219 SCANNER. In bash no root.

Proof-of-concept exploit for CVE-2026-44788, demonstrating vulnerability exploitation in C# for security testing and validation.

Proof-of-concept exploit for CVE-2018-1000533, a remote code execution vulnerability in GitList 0.6.0 via unsanitized input in the search function,…

test code for cve-2024-6387

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec