
CVE-2025-70830
A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to…

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to…

Proof-of-concept exploit for CVE-2026-25924, demonstrating administrative remote code execution in Kanboard through a missing access control check on…

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction

PoC for CVE-2019-16941

CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction

Frontend File Manager Plugin (WordPress) <= 23.6 - Unauthenticated Arbitrary File Deletion to RCE

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec


PoC Magento Session Reaper - CVE-2025-54236

CVE-2025-49113 - Roundcube <= 1.6.10 Post-Auth RCE via PHP Object Deserialization

Proof-of-concept exploit for CVE-2022-23935 targeting ExifTool 12.37, demonstrating arbitrary code execution via crafted image metadata.

A proof of concept for Joomla's CVE-2015-8562 vulnerability

Proof-of-concept exploit for CVE-2026-22686, demonstrating remote code execution in Node.js ESM sandboxes via process.getBuiltinModule to bypass…

Adobe ColdFusion CVE-2023-26360/CVE-2023-29298 自动化实现反弹

Exploit on the default cache of superset by using pickle

CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin

PoC de CVE-2026-0848: validacion de entrada indebida en NLTK que permite ejecucion de codigo via StanfordSegmenter.

This is POC repo for CVE-2026-48208