
CVE-2026-28134
JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

halo cms plugin 1-request rce from a url, PoC + exploit chain

Generates per-device kernel offsets from boot.img and compiles a preload library to exploit CVE-2026-43499 Android arm64 local privilege escalation.

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

Exploits unauthenticated RCE in Apache Gravitino < 1.2.1 via H2 JDBC INIT; hosts SQL/Java payloads, executes commands, and exfiltrates output over…

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

CVE-2026-39154 · Stored XSS in CometChat JS SDK

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

PoC exploit for CVE-2022-3218 targeting WiFi Mouse Server 1.7.8.5, achieving RCE via keystroke injection and in-memory PowerShell payload delivery…

Exploit kit for Exynos 9830 bootROM that delivers signed-boot bypass, custom key injection, and memory-dump payloads for Samsung SM-G985F devices.

Loads and runs ELF objects entirely in memory across x86_64/x86 Linux systems, resolving libc symbols at runtime for stealthy post-exploitation…

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

CVE-2017-9805-Exploit

CVE-2025-55182 — Next.js Flight Deserialization RCE exploit with interactive shell, single-command execution and multi-payload reverse shell chain.…