
CVE-2026-23885
Proof-of-concept exploit for CVE-2026-23885, an authenticated RCE in AlchemyCMS via eval() injection, with technical analysis and remediation…

Proof-of-concept exploit for CVE-2026-23885, an authenticated RCE in AlchemyCMS via eval() injection, with technical analysis and remediation…


Proof-of-concept exploit for CVE-2018-6574 targeting a Go web server vulnerability. Demonstrates remote code execution via crafted HTTP requests.

Proof-of-concept exploit for CVE-2018-7211 targeting iDashboards 9.6b. Python script for encrypting/decrypting strings to demonstrate the…

CVE-2017-13286 Poc(can not use)

Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you…


Proof-of-concept exploit for CVE-2016-3714, a remote code execution vulnerability in ImageMagick's MVG file processing. Demonstrates shell command…

Arbitrary deserialization that can be used to trigger SQL injection and even Code execution

Proof-of-concept exploit for CVE-2019-0207 in Apache Tapestry 5.4.4, demonstrating remote code execution via deserialization vulnerability.

A Python-based security scanner for detecting and exploiting **React Server Components (RSC)** vulnerabilities in Next.js applications. This tool…

# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor…

1C-Bitrix <= 25.100.500 (Translate Module) Remote Code Execution Vulnerability

Spring Cloud Gateway远程代码执行漏洞

unzip-stream file write/overwrite vulnerability

Android platform framework patch for CVE-2023-21281, addressing a security vulnerability in the Android framework.

Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Upload

Analyzes and addresses CVE-2023-47108, providing vulnerability assessment and remediation guidance for affected systems.