
CVE-2023-46615
KD Coming Soon <= 1.7 - Unauthenticated PHP Object Injection via cetitle

KD Coming Soon <= 1.7 - Unauthenticated PHP Object Injection via cetitle

Proof-of-concept for remote code execution in CheckMK Raw Edition 1.5.0–1.5.0p25 via misconfigured Dokuwiki embedded application allowing PHP code…

Detailed CVE-2017-14105 disclosure for Aerohive HiveManager Classic privilege escalation via malicious backup archive upload enabling JSP webshell…

CVE-2024-52550

Public disclosure for CVE-2023-31584.

C-based exploit for CVE-2023-6546, providing proof-of-concept code to demonstrate and test the vulnerability in affected systems.

Proof-of-concept exploit for CVE-2024-21644, demonstrating remote code execution vulnerability with Python-based automation and colored output.

Laravel RCE CVE-2021-3129

Formidable Forms <= 6.1.2 - Unauthenticated PHP Object Injection

NextMove Lite < 2.18.0 - Subscriber+ Arbitrary Plugin Installation/Activation

CVE-2018-8097 PoC

Proof-of-concept for CVE-2025-55182 (React2Shell): unauthenticated RCE in React Server Components / Next.js via Flight protocol deserialization.

Proof-of-concept exploit for CVE-2026-25546, demonstrating OS command injection in godot-mcp via malicious projectPath parameter, with Python PoC and…

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's 'go get' command, demonstrating exploitation via malicious…

Proof-of-concept exploit for CVE-2025-51482, demonstrating remote code execution via unsafe exec() usage and sandbox bypass in the Letta AI agent…

Proof-of-concept exploit for CVE-2023-4634, a remote code execution vulnerability in the WordPress Media Library Assistant plugin. Includes a…

VMWare Horizon client for macOS LPE due to an XPC logic flaw. Belated POC for an 0-day I responsibly disclosed to Omnissa.

POC for CVE-2022-22963