
SGLang-0.5.9-RCE
Proof of Concept exploitation of CVE-2026-5760 - RCE in SGLang 0.5.9 via malicious GGUF

Proof of Concept exploitation of CVE-2026-5760 - RCE in SGLang 0.5.9 via malicious GGUF

Proof of concept / CTF script for exploiting CVE-2022-46169 in Cacti, versions >=1.2.22

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

Exploit for the PHP 8.1.0-dev backdoor vulnerability (CVE-2021-21707)

Created this exploit for the Hack The Box machine, Blurry.

PoC to CVE-2023-30547 (Library vm2)

This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious…

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

A malicious LDAP server for JNDI injection attacks

Educational exploit for CVE-2023-50164 (Apache Struts 2) demonstrating path traversal and remote code execution via malicious file upload, designed…

Proof-of-concept exploit for CVE-2021-29447, an authenticated XXE vulnerability in WordPress 5.6-5.7. Includes lab setup, malicious WAV generation,…

Proof-of-concept exploit for CVE-2024-23724 in Ghost CMS, demonstrating privilege escalation via malicious SVG profile image upload.

Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE

Re-play Security Events

WordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerability

this is my simple article about CVE 2022-30190 (Follina) analysis. I use the lab from Letsdefend.

Python exploit script for CVE-2023-33733 targeting web applications. Automates authentication, session extraction, and reverse shell delivery for…

CVE-2025-4138 - Python Arbitrary file write outside extraction directory