
vulnerable-next-js-poc
Proof-of-concept exploit for CVE-2025-55182 (React2Shell), a critical RCE vulnerability in React Server Components via unsafe deserialization.…

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), a critical RCE vulnerability in React Server Components via unsafe deserialization.…

Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output…

Proof-of-concept exploit for CVE-2026-13181 affecting Telerik web components, demonstrating remote code execution via crafted requests.

React2Shell (CVE-2025-66478): A Python-based Proof of Concept for Critical Remote Code Execution (RCE) in Next.js Server Components. Features an…

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

React Server Components 远程代码执行漏洞(CVE-2025-55182)

Poc for CVE-2025-55182 (remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including…

Scanner and exploit toolkit for CVE-2025-55182, a critical pre-auth RCE in React Server Components. Includes detection, interactive shell, Docker…

WEB-CLI_RCE_React2Shell is an educational PoC exploit tool for CVE-2025-55182, a critical Prototype Pollution flaw in Next.js applications using…

Go-based proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components. Features vulnerability checking, command execution, memory…

Identifying all log4j components across on local windows servers. CVE-2021-44228

Working Proof of Concept (PoC) for CVE-2025-55182 (React2Shell) - Unauthenticated Remote Code Execution in Next.js 15.0.0 via React Server Components

Proof-of-concept exploit for CVE-2025-55182/66478, a React Server Components deserialization RCE, delivering a reverse shell via crafted multipart…

Security research lab for CVE-2025-55183 and CVE-2025-55184 in React Server Components

React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0, including react-server-dom-parcel, react-server-dom-turbopack, and…

CVE-2023-34212: Java Deserialization via JNDI Components in Apache NiFi

Proof-of-concept exploit for CVE-2026-21055 demonstrating arbitrary command execution via improperly exported Android components in Samsung Bixby.…

Automated exploit tool for CVE-2025-55182 in Next.js React Server Components. Enables remote command execution with built-in WAF bypass, custom…