
CVE-2025-27237
CVE 2025 27237 Zabbix LPE proof of concept.

CVE 2025 27237 Zabbix LPE proof of concept.

Proof-of-concept exploit for CVE-2026-48030, a critical OS command injection in Pheditor 2.0.1-2.0.3. Includes vulnerable code analysis, PoC script,…

Secure coding project, research on CVE-2019-17498 and implement a player score function written in C.

Security advisory for CVE-2026-66731 with root cause analysis, PoC exploit, and fix suggestions for facil.io HTTP/1.1 chunked encoding parser bug.

Automated scanner and exploit for CVE-2026-27384, an unauthenticated RCE in W3 Total Cache via mfunc/eval() injection. Features auto-detection, 48…

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

Python exploit for CVE-2026-46725, achieving unauthenticated remote code execution in TYPO3 ceselector extension via PHP object injection and Monolog…

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

Documentation and reproduction code for CVE-2025-67221, a denial-of-service vulnerability in orjson's dumps() function caused by uncontrolled…

Easy setup of static analysis tools for Android and Java projects.

Multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_department in Customer Support System 1.0 allow authenticated…

Assets Management System 1.0 is vulnerable to SQL injection via the id parameter in delete.php


CVE-2025-49113 - Roundcube <= 1.6.10 Post-Auth RCE via PHP Object Deserialization

CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

Technical write-up of CVE-2026-26717, an HMAC timing attack in OpenFUN Richie LMS webhook authentication, including vulnerable code, impact, and fix…