
CVE-2019-19511
Chevereto - 1.0.0 Free - 1.1.4 Free, 3.13.4 Core, Remote Code Execution

Chevereto - 1.0.0 Free - 1.1.4 Free, 3.13.4 Core, Remote Code Execution

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

Proof-of-concept exploit for CVE-2023-29007, a Git arbitrary configuration injection vulnerability. Demonstrates exploitation on Windows systems for…

Proof-of-concept exploit for CVE-2018-20718, a PHP object injection vulnerability in Pydio before 8.2.1 enabling unauthenticated remote code…

CVE-2025-49113 - Roundcube <= 1.6.10 Post-Auth RCE via PHP Object Deserialization

PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required…

A PoC for the Bamboo deserialization exploit

Pre-authentication remote code execution exploit for FUEL CMS 1.4.1 (CVE-2018-16763). Python-based proof-of-concept for security testing and…

WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型…

An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.

ColorMag <= 3.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation


Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render…

Exploit tool for CVE-2024-36104 targeting Apache OFBiz code execution vulnerability. Supports single and batch URL scanning with proxy and threading…

Vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or…

Proof-of-concept exploit for CVE-2022-23935 targeting ExifTool 12.37, demonstrating arbitrary code execution via crafted image metadata.

A proof of concept for Joomla's CVE-2015-8562 vulnerability
