
CVE-2022-22965_Spring4Shell
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

Proof-of-concept exploit demonstrating UMCI bypass in Internet Explorer using JScript and ActiveX to execute arbitrary binaries, targeting Windows…

A critical Remote Code Execution (RCE) vulnerability has been identified in PluXML CMS version 5.8.22. This vulnerability allows authenticated…

Exploit for CVE-2025-3248: injects crafted Python payloads into an unauthenticated API code endpoint to execute arbitrary commands on the target…

Remote command execution in Golang go get command allows an attacker to gain code execution on a system by installing a malicious library.

GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization

Proof-of-concept exploit for CVE-2026-22686, demonstrating remote code execution in Node.js ESM sandboxes via process.getBuiltinModule to bypass…

Proof-of-concept exploit for CVE-2026-33937, a Handlebars AST injection vulnerability leading to remote code execution in Node.js. Demonstrates…

Obfuscate a python code 2.x and 3.x

Multifunctional java deobfuscation tool suite

Finding Java/C# gadget chains with CodeQL

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

CVE-2022-41852 Proof of Concept (unofficial)

POC for RCE vulnerability in ParseExcel library, and ParseXLSX too, as a depending library

WordPress Elementor 3.6.0 3.6.1 3.6.2 RCE POC