
0-click-RCE-Exploit-for-CVE-2024-9932
Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

Simple payload builder

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

A prompt injection in a code‑review bot that executes AI‑generated fixes in a sandbox. The sandbox uses a blacklist to prevent dangerous commands,…

PoC repository for CVE-2025-68147: Stored Cross-Site Scripting (XSS) in OpenSourcePOS. Vulnerability allows privilege escalation via malicious…

A complete walkthrough and exploit for CVE-2019-9978 - Unauthenticated Remote Code Execution in Social Warfare WordPress plugin ≤ 3.5.2. Includes…

CVE-2018-6574 POC : golang 'go get' remote command execution during source code build

Publicly disclosed Proof-of-Concept (POC) exploit for the [email protected] version

CVE-2025-55182 检测方式和攻击利用

Studio 3T v.2025.1.0

MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS

PoC for CVE-2026-12191


Detection for CVE-2025-42944



CVE-2021-46362: FreeMarker Server-Side Template Injection in Magnolia CMS