
CVE-2025-53770
Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)

Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)

Spring-Kafka-Deserialization-Remote-Code-Execution

Collection of different ways to execute code outside of the expected entry points

This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux…

CVE 2025 27237 Zabbix LPE proof of concept.

CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE

CVE-2019-17564:Apache Dubbo反序列化漏洞

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

GiveWP PHP Object Injection exploit

Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)

Hotel Druid 3.0.3 Code Injection to Remote Code Execution

CVE-2020-11975 CVE-2020-13942

Proof-of-concept exploit for CVE-2021-43609 demonstrating SQL injection to file read to remote code execution chain against Spiceworks help desk…

Proof-of-concept exploit for CVE-2024-44902, a deserialization vulnerability in ThinkPHP v6.1.3–v8.0.4 enabling remote code execution via crafted…

Proof of Concept for a Server-Side Template Injection (SSTI) vulnerability in Calibre’s Templite engine (GHSA-xrh9-w7qx-3gcc). Demonstrates arbitrary…

Exploit for CVE-2026-3300, an unauthenticated stored XSS leading to RCE in Everest Forms Pro WordPress plugin, with a Python script to generate a…

Python proof-of-concept exploit for CVE-2023-6553, demonstrating unauthenticated remote code execution via PHP filter chain in the Backup Migration…

CVE-2023-46818 - ISPConfig PHP Code Injection PoC Exploit (Bash)