
CVE-2018-19276
CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE

CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)

Verifed Proof of Concept on CVE-2022-24086

PHPMailer < 5.2.18 Remote Code Execution Exploit

Advisory and proof of concept for CVE-2019-12180, demonstrating arbitrary Groovy code execution in SoapUI and ReadyAPI via malicious project files.

Proof-of-concept exploit for CVE-2024-44902, a deserialization vulnerability in ThinkPHP v6.1.3–v8.0.4 enabling remote code execution via crafted…

[PoC] Privilege escalation & code execution via LFI in PwnDoC

Mautic < 5.2.3 Authenticated RCE

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction

Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell…

Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability

Publicly disclosed Proof-of-Concept (POC) exploit for the [email protected] version

Proof-of-concept for CVE-2025-65741 demonstrating dylib injection in Sublime Text 3 on macOS via unsigned code, with a compiled .dylib payload and…

PoC exploit for CVE-2021-36981: authenticated remote code execution via unsafe Java deserialization in Verinice.Pro using a C3P0 gadget chain.

Proof-of-concept exploit for CVE-2025-50472, a deserialization RCE vulnerability in ModelScope ms-swift's ModelFileSystemCache via malicious .mdl…