
CVE-2020-1947
Apache ShardingSphere UI YAML解析远程代码执行漏洞

Apache ShardingSphere UI YAML解析远程代码执行漏洞

Source code for the Binaries of OWASP WrongSecrets

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

CVE-2019-17564:Apache Dubbo反序列化漏洞

Provides a quick workaround for the segfault bug in Ruby (CVE-2009-1904)

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

Proof of Concept exploitation of CVE-2026-5760 - RCE in SGLang 0.5.9 via malicious GGUF

Exploiting CVE-2022-0847 - written by : Antonius (w1sdom)

The latest workaround for the "Query is corrupt" error introduced with CVE-2019-1402

Proof-of-concept exploit for CVE-2018-20718, a PHP object injection vulnerability in Pydio before 8.2.1 enabling unauthenticated remote code…

CVE-2025-49113 – Roundcube ≤1.6.10 post-auth RCE via PHP object deserialization (HackTheBox CTF)

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

CVE-2022-40635: Groovy Sandbox Bypass in CrafterCMS

Educational lab demonstrating CVE-2025-55182: Critical RCE in React Server Components via prototype pollution in the Flight protocol

A bash script to scan your server for React applications vulnerable to **CVE-2025-55182** — a critical remote code execution vulnerability (CVSS…

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.