
CVE-2026-28134
JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

Proof-of-concept exploit for JetBrains TeamCity that performs unauthenticated remote code execution via agent polling protocol deserialization,…


Web Application Exploit Development

Proof-of-concept exploit for CVE-2019-10068, a deserialization RCE in Kentico CMS, that uploads an ASP.NET webshell for authorized security testing.


Magento ver. 2.4.6 - XSLT Server Side Injection


That repository contains my updates to the well know java deserialization exploitation tool ysoserial.

RCE exploit for dompdf

fastjson-1.2.58-rce with h2 database

WP GDPR Compliance <= 1.4.2 - Remote Code Execution (exploiter)


React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

POC for Spring Kafka Deserialization Vulnerability CVE-2023-34040