
CVE-2016-2173
Proof-of-concept exploit for CVE-2016-2173, demonstrating remote code execution via unsafe deserialization in Spring AMQP using Commons Collection…

Proof-of-concept exploit for CVE-2016-2173, demonstrating remote code execution via unsafe deserialization in Spring AMQP using Commons Collection…

Nuclei template to detect CVE-2025-24016 unsafe deserialization RCE in Wazuh servers via a crafted JSON payload that triggers a NameError.


Advisory and proof of concept for CVE-2019-12180, demonstrating arbitrary Groovy code execution in SoapUI and ReadyAPI via malicious project files.


Python-based RCE exploit for CVE-2026-42588 targeting Apache ActiveMQ Jolokia. Features check-only mode, malicious XML generation, and support for…

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful…

PoC for CVE-2020-28032 (It's just a POP chain in WordPress < 5.5.2 for exploiting PHP Object Injection)

(CVE-2017-9841) PHPUnit_eval-stdin_php Remote Code Execution

PHP object injection exploit for CVE-2026-49105 targeting WP Zendesk plugin. Provides proof-of-concept code for security testing and vulnerability…

Python proof-of-concept exploit for CVE-2023-6553, demonstrating unauthenticated remote code execution via PHP filter chain in the Backup Migration…

PoC for CVE-2021-2471 - XXE in MySQL Connector/J

CVE-2022-39425 PoC

CVE-2023-46818 - ISPConfig PHP Code Injection PoC Exploit (Bash)

Proof-of-concept exploit for CVE-2023-46694: authenticated remote code execution via arbitrary file upload in Vtenext 21.02 Ckeditor file manager.

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to…

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.