
CVE-2022-1329
CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and…

CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and…

Studio 3T v.2025.1.0

MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS

Proof-of-concept demonstrating remote code execution in lodash template via prototype pollution, with detailed analysis of the attack flow and…

CVE-2022-25845 (fastjson 1.2.80) exploit for Spring environments with step-by-step PoC, file read, and arbitrary file write via Jackson/commons-io…

Proof-of-concept exploit for CVE-2025-48543, written in C++. Demonstrates exploitation of a specific vulnerability for security testing and research…

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

Apache Solr Backup/Restore APIs RCE Poc (CVE-2023-50386)

Apache/Alibaba Dubbo <= 2.7.3 PoC Code for CVE-2021-25641 RCE via Deserialization of Untrusted Data; Affects Versions <= 2.7.6 With Different Gadgets

SolarWinds Orion Platform ActionPluginBaseView 反序列化RCE

CVE-2024-28397: js2py sandbox escape, bypass pyimport restriction.

Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)

Spring-Kafka-Deserialization-Remote-Code-Execution

CVE-2018-6574 POC : golang 'go get' remote command execution during source code build

Exploit script for CVE-2021-22204, an ExifTool RCE via malicious DjVu files, with manual exploitation steps and reverse shell payloads.

PoC for CVE-2022-23940

This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux…

CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface