
CVE-2023-6553-PoC
Python proof-of-concept exploit for CVE-2023-6553, demonstrating unauthenticated remote code execution via PHP filter chain in the Backup Migration…

Python proof-of-concept exploit for CVE-2023-6553, demonstrating unauthenticated remote code execution via PHP filter chain in the Backup Migration…

PoC for CVE-2021-2471 - XXE in MySQL Connector/J

CVE-2022-39425 PoC

CVE-2023-46818 - ISPConfig PHP Code Injection PoC Exploit (Bash)

Proof-of-concept exploit for CVE-2023-46694: authenticated remote code execution via arbitrary file upload in Vtenext 21.02 Ckeditor file manager.

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to…

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

NodeJS + Postgres (Remote Code Execution) 🛰

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0, including react-server-dom-parcel, react-server-dom-turbopack, and…

CVE-2023-34212: Java Deserialization via JNDI Components in Apache NiFi

Proof-of-concept exploit for CVE-2019-12086: Jackson databind deserialization vulnerability enabling arbitrary file read via rogue MySQL server when…

批量检测Spring Cloud Gateway 远程代码执行漏洞 Spring_Cloud_Gateway_RCE_POC-CVE-2022-22947

Proof-of-concept exploit for CVE-2018-1273, a Spring Data Commons property binder vulnerability leading to remote code execution via crafted HTTP…

Remote Code Execution (RCE) via Polyglot File Attack and Null Byte Injection on Laravel FileManager

PoC for CVE-2022-34265

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction

xmlrpc common deserialization vulnerability