
CVE-2024-34716
Proof-of-concept exploit for CVE-2024-34716, a PNG-driven XSS to RCE chain in PrestaShop 8.1.5, enabling remote code execution via crafted image…

Proof-of-concept exploit for CVE-2024-34716, a PNG-driven XSS to RCE chain in PrestaShop 8.1.5, enabling remote code execution via crafted image…

Proof-of-concept and technical analysis of CVE-2023-25813, a SQL injection vulnerability in Sequelize ORM versions prior to 6.19.1, including…

Proof-of-concept exploit for CVE-2026-48030, a critical OS command injection in Pheditor 2.0.1-2.0.3. Includes vulnerable code analysis, PoC script,…

Detailed technical write-up and proof-of-concept exploit for CVE-2023-33733, a remote code execution vulnerability in the Reportlab Python library…

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

Details about the Blind RCE issue(SPX-GC) in SPX-GC

A collection of my Semgrep rules to facilitate vulnerability research.

SQL / SQLI tokenizer parser analyzer

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Technical analysis of CVE-2025-66628, an integer overflow in ImageMagick's TIM parser leading to out-of-bounds reads, with root cause, exploitation…

Technical Details and Exploit for CVE-2025-50460

Proof of concept for SQL injection vulnerability in School Task Manager System, demonstrating exploitation and providing technical details for…

Proof-of-concept exploit for SQL injection vulnerability in Online Timesheet App, demonstrating the attack and providing technical details for…

POC for CVE-2018-0824

CVE-2023-46818 - ISPConfig PHP Code Injection PoC Exploit (Bash)

CVE-2025-49113 – Roundcube ≤1.6.10 post-auth RCE via PHP object deserialization (HackTheBox CTF)

Unauthenticated remote code execution exploit for Vehicle Management System in PHP via unrestricted file upload in newdriver.php and newvehicle.php,…