
CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit
PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0

PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0

Hotel Druid 3.0.3 Code Injection to Remote Code Execution

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

This repository contains a Proof of Concept (PoC) demonstrating a critical vulnerability in givanz Vvveb 1.0.5. The vulnerability allows an…

WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

CVE-2026-25632 — Fix Unsafe JSON Deserialization Leading to Remote Code Execution

[CVE-2024-23897] Jenkins CI Authenticated Arbitrary File Read Through the CLI Leads to Remote Code Execution (RCE)

[CVE-2017-9822] DotNetNuke Cookie Deserialization Remote Code Execution (RCE)

A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)


Handlebars CVE-2021-23369 Vulnerability

Flex QR Code Generator <= 1.2.6 - Unauthenticated Arbitrary File Upload

Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action


The code for personally reproducing the corresponding vulnerability