
CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit
CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit

CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit

Cargo exploit from CVE-2023-38497

Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability

Proof‑of‑concept description for CVE‑2025‑47916, a Remote Code Execution vulnerability affecting Invision Community 5.0.0–5.0.6 via unsafe template…

Proof-of-concept exploit for a critical RCE vulnerability in n8n (CVE-2025-68613), demonstrating arbitrary command execution via expression injection…

PoC exploit for CVE-2021-36981: authenticated remote code execution via unsafe Java deserialization in Verinice.Pro using a C3P0 gadget chain.

A critical Remote Code Execution (RCE) vulnerability has been identified in PluXML CMS version 5.8.22. This vulnerability allows authenticated…

Proof-of-concept exploit for unauthenticated remote code execution in SPIP < 4.2.1 via PHP object injection in the password reset form. Provides…

Proof-of-concept for CVE-2025-55182 (React2Shell): unauthenticated RCE in React Server Components / Next.js via Flight protocol deserialization.

Proof-of-concept exploit for CVE-2025-50472, a deserialization RCE vulnerability in ModelScope ms-swift's ModelFileSystemCache via malicious .mdl…

CVE-2025-55816 HotelDruid 3.0.7

Remote command execution in Golang go get command allows an attacker to gain code execution on a system by installing a malicious library.

Exploit for CVE-2025-3248: injects crafted Python payloads into an unauthenticated API code endpoint to execute arbitrary commands on the target…


Vulnerabilidad CVE-2024-24926 afecta al tema Brooklyn de WordPress

Proof-of-concept exploit for CVE-2024-28397, a sandbox escape in js2py allowing remote code execution via crafted JavaScript, with a dynamic patch…

GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization

Proof-of-concept exploit for CVE-2024-4577 enabling remote code execution in vulnerable PHP versions 8.1-8.3. Includes customizable arguments for…