
CVE-2022-1329
WordPress Elementor 3.6.0 3.6.1 3.6.2 RCE POC

WordPress Elementor 3.6.0 3.6.1 3.6.2 RCE POC

PoC of Spring AMQP Deserialization Vulnerability (CVE-2023-34050)

CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE

Proof-of-concept exploit for CVE-2024-38475 targeting Apache HTTP Server mod_rewrite improper escaping, enabling URL-to-filesystem mapping for code…

CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface

ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

Proof-of-concept exploit for CVE-2022-22980, a remote code execution vulnerability in Spring Data MongoDB via SpEL injection in the username…

Trying to reproduce CVE-2021-43908

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if…

CVE-2024-37032 (Probllama) PoC for Ollama ≤0.1.33: path traversal and arbitrary file write via model digest handling, leading to automated privilege…

GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425)

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…


FUDForum 3.0.9 - XSS / Remote Code Execution (CVE-2019-18873, CVE-2019-18839)

Spring cloud gateway code injection : CVE-2022-22947

Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution

Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)

Nuclei template for detecting react2shell (CVE-2025-55182 & CVE-2025-66478)