
CVE-2024-9593
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution

Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution

Nuclei template for detecting react2shell (CVE-2025-55182 & CVE-2025-66478)

Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)

Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python

CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本

PoC for CVE-2025-55183

PHP CGI Argument Injection.

Proof-of-concept exploit for CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow, demonstrating code injection via the…

pluck-CMS-4.7.20-code-injection-vulnerability

Proof-of-concept exploit for Jackson-databind remote code execution vulnerability (CVE-2019-14439) targeting insecure deserialization in Java…

Verifed Proof of Concept on CVE-2022-24086

It is a simple PoC of Improper Input Validation in python-gnupg 0.4.3 (CVE-2019-6690).

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

Stored XSS via Location Title in DPCalendar Free

Hotel Druid 3.0.3 Code Injection to Remote Code Execution

Test wether you're exposed to ghost (CVE-2015-0235). All kudos go to Qualys Security

Proof-of-concept exploit for authenticated remote code execution via XSLT injection in Lutece Core, demonstrating command execution through crafted…

Proof-of-concept exploit for arbitrary file read in mcp-atlassian via path traversal in confluence_upload_attachment, with analysis and reproduction…