
CVE-2026-11551-PoC
Proof-of-concept exploit for CVE-2026-11551, an unauthenticated privilege escalation vulnerability in the Branda White Label plugin for WordPress,…

Proof-of-concept exploit for CVE-2026-11551, an unauthenticated privilege escalation vulnerability in the Branda White Label plugin for WordPress,…

CVE-2025-51458 - DB-GPT Pre-Auth SQL Injection PoC

Exploit code for CVE-2018-6574, a Go language vulnerability allowing arbitrary code execution via crafted import paths.


Proof-of-concept exploit for Apache Struts2 remote code execution vulnerability CVE-2020-17533, leveraging OGNL expression injection for…

Studio 3T v.2025.1.0

This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).

CVE-2025-6384: Groovy Sandbox Bypass 2 in CrafterCMS

Confluence server webwork OGNL injection

Proof-of-concept exploit for CVE-2022-26884 targeting Apache DolphinScheduler, enabling remote code execution via crafted requests to the workflow…

Proof-of-concept exploit for CVE-2022-34662 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in the…

StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.4.0 - Authenticated (Subscriber+)…

Spring Cloud Gateway Actuator API SpEL Code Injection.

Ruby-based exploit for CVE-2015-0235 (Ghost) targeting glibc gethostbyname buffer overflow for remote code execution on vulnerable systems.

Exploit for Jenkins CVE-2015-8103, a remote code execution vulnerability in the Jenkins CLI. Enables authenticated attackers to execute arbitrary…

yasa

CVE-2021-46071 - A Stored Cross Site Scripting (XSS) vulnerability exists in Vehicle Service Management System 1.0 via the Category List Section in…