
CVE-2025-55182
Pre-auth RCE in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0.

Pre-auth RCE in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0.

CVE-2020-36179~82 Jackson-databind SSRF&RCE

Just a normal flask web app to understand win32api with code snippets and references.

Small example repo for looking into log4j CVE-2021-44228

Breaking git with a carriage return and cloning RCE

All-in-one macOS binary analysis: Mach-O parsing, ARM64 disassembly, code signatures, and debugging.

Template Injection in Email Templates leads to code execution on Jira Service Management Server

Proof-of-concept exploit for CVE-2023-29007, a Git arbitrary configuration injection vulnerability. Demonstrates exploitation via crafted repository…

Proof of Concept for the Apache commons-text vulnerability CVE-2022-42889.

CVE-2020-35728 & Jackson-databind RCE

PoC exploit for CVE-2020-8840: JNDI injection leading to remote code execution in FasterXML jackson-databind. Includes environment setup, exploit…

Spring Cloud Netflix Hystrix Dashboard template resolution vulnerability CVE-2021-22053

Apache Karaf XXE Vulnerability (CVE-2018-11788)

CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad

Source code for the Binaries of OWASP WrongSecrets

Proof-of-concept exploit for CVE-2026-48909: unauthenticated remote code execution via PHP object injection in JoomShaper SP LMS. Includes detection,…

Intentionally vulnerable Next.js application demonstrating CVE-2025-55182 RCE via unsafe deserialization in React Server Components. Includes exploit…

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)