
CVE-2025-27636-RCE-in-Apache-Camel
Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Demonstrates CVE-2026-11108 integer overflow in kmalloc simulation, causing heap overflow and potential arbitrary code execution from crafted…

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

Proof of Concept for Stored-XSS on Vulnerable WP-Statistics Plugin known as CVE-2025-9816

Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE

Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713

PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain…

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…

Exploit for CVE-2004-1561 Icecast header overwrite buffer overflow on Windows, providing remote code execution with a reverse shell payload.

Proof-of-concept exploit for CVE-2024-10410: unrestricted file upload in Online Hotel Reservation System. Demonstrates bypass of image validation via…

A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)

PoC for triggering buffer overflow via CVE-2020-0796

CVE-2022-26134 Confluence OGNL Injection POC

Proof-of-concept exploit for Apache Struts2 S2-045 (CVE-2017-5638) remote code execution vulnerability via malicious Content-Type header.

Icecast Header Overwrite buffer overflow RCE < 2.0.1 (Win32)