
CVE-2025-59470-PostgreSQL-Command-Injection
Proof-of-concept exploit for CVE-2025-59470, a command injection vulnerability in PostgreSQL's pg_backup extension, allowing authenticated backup…

Proof-of-concept exploit for CVE-2025-59470, a command injection vulnerability in PostgreSQL's pg_backup extension, allowing authenticated backup…

Proof-of-concept exploit for CVE-2024-24725, demonstrating a web application vulnerability with PHP-based exploitation code for security testing and…

C-based exploit for CVE-2023-6546, providing proof-of-concept code to demonstrate and test the vulnerability in affected systems.

Laravel RCE CVE-2021-3129

Formidable Forms <= 6.1.2 - Unauthenticated PHP Object Injection

CVE-2021-46364: YAML Deserialization in Magnolia CMS

SpringCloudGatewayRCE / Code By:Jun_sheng

Detailed CVE-2017-14105 disclosure for Aerohive HiveManager Classic privilege escalation via malicious backup archive upload enabling JSP webshell…

CVE-2018-8097 PoC

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

CVE-2024-52550

Detailed technical analysis of CVE-2022-24760, a prototype pollution vulnerability in parse-server leading to remote code execution via BSON…

Proof-of-concept exploit for CVE-2018-16858, demonstrating the vulnerability and providing exploitation code for security testing and research.

Proof-of-concept exploit for CVE-2023-4634, a remote code execution vulnerability in the WordPress Media Library Assistant plugin. Includes a…

Proof-of-concept for CVE-2025-55182 (React2Shell): unauthenticated RCE in React Server Components / Next.js via Flight protocol deserialization.

Proof-of-concept exploit for CVE-2025-51482, demonstrating remote code execution via unsafe exec() usage and sandbox bypass in the Letta AI agent…

POC for CVE-2022-22963

Proof-of-concept exploit for CVE-2026-25546, demonstrating OS command injection in godot-mcp via malicious projectPath parameter, with Python PoC and…