
CVE-2021-46362
CVE-2021-46362: FreeMarker Server-Side Template Injection in Magnolia CMS

CVE-2021-46362: FreeMarker Server-Side Template Injection in Magnolia CMS

Proof-of-concept exploit for CVE-2017-1000117, demonstrating a remote code execution vulnerability in Git.

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.3 - Unauthenticated PHP Object Injection

DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection

Spring4Shell is a critical RCE vulnerability in the Java Spring Framework and is one of three related vulnerabilities published on March 30

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's net/http package via crafted HTTP requests.

Exploit for the Rails CVE-2019-5420

Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

Dolibarr 17.0.0 PHP Code Injection Exploit

Proof-of-concept exploit for CVE-2020-5245, demonstrating expression language injection in Dropwizard REST endpoints via crafted HTTP parameters.

CVE-2024-56115 proof-of-concept for Amiro.CMS XSS and OS command injection vulnerabilities, enabling security researchers to test and validate…

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's net/http package via crafted HTTP/2 requests.

PoC for CVE-2024-23998

Partners <= 0.2.0 - Unauthenticated PHP Object Injection

PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation

Wordpress IgniteUp plugin < 3.4.1 allows unauthenticated users to arbitrarily delete files on the webserver possibly causing DoS.

CVE-2022-22947 exploit script

PoC for CVE-2022-21340