
CVE-2026-39938
Detailed CVE-2026-39938 vulnerability report for Cacti ≤1.2.30, demonstrating unauthenticated LFI chained to OS command injection RCE with PoC, root…

Detailed CVE-2026-39938 vulnerability report for Cacti ≤1.2.30, demonstrating unauthenticated LFI chained to OS command injection RCE with PoC, root…

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.

Proof-of-concept exploit for CVE-2026-48030, a critical OS command injection in Pheditor 2.0.1-2.0.3. Includes vulnerable code analysis, PoC script,…

Automated PoC script for CVE-2023-36845, exploiting a PHP flaw in Juniper Junos OS J-Web to remotely modify PHPRC and achieve code injection on…

OS Command Injection Vulnerability via Plugin Execution in Figma Desktop Application

CVE-2024-56115 proof-of-concept for Amiro.CMS XSS and OS command injection vulnerabilities, enabling security researchers to test and validate…

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

CVE-2022-40635: Groovy Sandbox Bypass in CrafterCMS

Advisory for pdf-image ⌯⌲ 10 000 weekly downloads

Advisory for textract ⌯⌲ 15 000 weekly downloads

Second CVE still Remote Code Execution

cve-2025-4615 poc & deep dive


Advisory for node-tesseract-ocr ⌯⌲ 50 000 weekly downloads

CVE-2025-6384: Groovy Sandbox Bypass 2 in CrafterCMS

UNIX-like reverse engineering framework and command-line toolset

Ghidra is a software reverse engineering (SRE) framework