
Grassmarlin-CVE-2026-6807-XXE-POC
Reverse Engineered based on CISA disclosure of new CVE

Reverse Engineered based on CISA disclosure of new CVE

React2Shell Exploitation Tool (CVE-2025-55182)


Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

POC to exploit WordPress 5.6-5.7 (PHP 8+) Authenticated XXE Injection.

POC of CVE-2026-51031 for arbitrary local file read


PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

Grafana Unauthorized arbitrary file reading vulnerability

Here you can find my relation about the project I made for the Internet Security course. Because I written it in Latex, you can also find the Latex…

Extraction of iMessage Data via XSS

Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in…

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

Arbitrary File Read and DoS in vendure-ecommerce exploit

Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel