
spring-amqp-deserialization
PoC of Spring AMQP Deserialization Vulnerability (CVE-2023-34050)

PoC of Spring AMQP Deserialization Vulnerability (CVE-2023-34050)

CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Proof-of-concept exploit for CVE-2024-38475 targeting Apache HTTP Server mod_rewrite improper escaping, enabling URL-to-filesystem mapping for code…

CVE-2025-55182 - React Server Components RCE Exploit & Scanner Supports external servers and CLI interface

Proof-of-concept exploit for CVE-2022-22980, a remote code execution vulnerability in Spring Data MongoDB via SpEL injection in the username…

ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

Trying to reproduce CVE-2021-43908

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if…

C-based proof-of-concept exploit for CVE-2023-6246, targeting a privilege escalation vulnerability in the Linux kernel's syscalls. Tested on Fedora…

CVE-2024-37032 (Probllama) PoC for Ollama ≤0.1.33: path traversal and arbitrary file write via model digest handling, leading to automated privilege…

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Execution (CVE-2021-21425)


Exploit code for CVE-2021-2394, a Java vulnerability, providing proof-of-concept for security testing and research.

FUDForum 3.0.9 - XSS / Remote Code Execution (CVE-2019-18873, CVE-2019-18839)

Spring cloud gateway code injection : CVE-2022-22947

GiveWP PHP Object Injection exploit