
CVE-2025-5781
Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted…

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted…

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

CVE-2026-1731 - Critical command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access due to unsafe Bash arithmetic…

Remote code execution vulnerability in OpenEMR <8.0.0.2.


PoC exploit for CVE-2026-33017: unauthenticated remote code execution in Langflow via malicious Python Custom Component injection, with built-in…

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

[CVE-2021-22123] Fortinet FortiWeb Authenticated OS Command Injection

A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.

Exploit for CyberPanel Pre-Auth RCE via Command Injection


CVE-2022-25765 pdfkit <0.8.6 command injection.

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

PoC for achieving RCE in Langflow versions <1.3.0

cve-2021-21985 exploit

An exploit for OpenTSDB <= 2.4.1 cmd injection (CVE-2023-36812/CVE-2023-25826) written in Fortran