
CVE-2020-12077
MapPress Maps Pro < 2.53.9 - Remote Code Execution (RCE) due to Incorrect Access Control in AJAX Actions

MapPress Maps Pro < 2.53.9 - Remote Code Execution (RCE) due to Incorrect Access Control in AJAX Actions



OpenSSL toolkit implementing SSL/TLS protocols and a general-purpose cryptography library with ciphers, digests, public key algorithms, and X.509…

cve-2025-4615 poc & deep dive

CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin

Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security…

Proof-of-concept demonstrating command injection in aws-mcp-server via shell=True, with analysis of the vulnerable code and the fix in v1.7.0.

Cargo exploit from CVE-2023-38497

Drop-in WordPress plugin that blocks the vulnerable Demo Import handler in FunnelForms Pro to mitigate Remote Code Execution (CVE-2026-39440).

CVE-2020-26259 &&XStream Arbitrary File Delete

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

struts1 CVE-2014-0114 classLoader manipulation vulnerability patch

Bash script to detect CVE-2025-55182 (React2Shell) and credential exposure in Next.js projects. Zero dependencies.

Apache synapse 反序列化 CVE–2017–15708

Python script to detect CVE-2018-16858 vulnerability in target systems, enabling rapid identification and assessment of this specific security flaw.