
CVE-2025-68664-LangGrinch-PoC
A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行

GitHub RCE via X-Stat Push Option Injection

Remote Code Execution in DbGate via functionName injection in the loadReader endpoint — CVSS 8.8

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE

Proof-of-concept exploit for Jenkins Templating Engine plugin sandbox bypass (CVE-2025-31722) enabling remote code execution via malicious Groovy…

Exploit for CVE-2023-27372 with interactiev shell

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

CVE-2026-25747 - Camel LevelDB Deserialization Vulnerability

Proof-of-Concept for CVE-2025-55182, a critical unauthenticated RCE in React Server Components.

Authenticated remote code execution exploit for Roundcube Webmail (CVE-2025-49113) via insecure deserialization. Includes session injection, gadget…

This technical research and review is for educational purposes on public code and constitutes Fair Dealing under the Copyright Act (Canada).

Researching on the vulnrability CVE-2023-26136

Browser-based scanner that audits GitHub repositories for known vulnerabilities in React and Next.js dependencies, checking all branches and…

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…