
CVE-2026-38526-KrayinCRM
Authenticated Arbitrary File Upload leading to Remote Code Execution Technical analysis and controlled reproduction of CVE-2026-38526 in Webkul…

Authenticated Arbitrary File Upload leading to Remote Code Execution Technical analysis and controlled reproduction of CVE-2026-38526 in Webkul…

Proof-of-concept exploit and Docker lab for CVE-2026-35194, an Apache Flink SQL code injection enabling remote code execution on TaskManagers via the…

GiveWP <= 4.16.7.1 Unauthenticated PHP Object Injection → RCE

The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samples are…

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit,…

Proof-of-concept exploit for CVE-2026-33229, an XWiki RCE via Apache Velocity sandbox bypass, with technical details and a working payload.

Remote Code Execution in Alexantr filemanager v1.0 via unrestricted file upload

SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution

Educational lab demonstrating unauthenticated RCE in Langflow via CVE-2026-33017, with automated VM setup and a PoC exploit for reverse shell.

Proof-of-concept and technical walkthrough demonstrating remote code execution in Sonatype Nexus, including EL injection debugging, BCEL payload…

Unauthenticated exploit for CVE-2026-68771, a pickle deserialization RCE in ComfyUI. Plants a crafted shard via /upload/image, triggers it through…

Proof of Concept for exploiting the CVE-2022-22965 (Spring4Shell) vulnerability in an isolated environment, with Remote Code Execution (RCE)…

Remote DLL Injection with Timer-based Shellcode Execution

Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for…

Implementing Ghostly-Hollowing using tampered syscalls for remote PE injection

Proof-of-concept exploit for CVE-2022-30190 (Follina), demonstrating remote code execution via crafted Microsoft Office documents using the ms-msdt…

[CVE-2021-21983] VMware vRealize Operations (vROps) Manager API Arbitrary File Write Leads to Remote Code Execution (RCE)

Java deserialization vulnerability exploitation tool with payload generators for multiple marshallers (Jackson, XStream, SnakeYAML) and JNDI…