
CVE-2026-20841
🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

Proof-of-concept exploit for JetBrains TeamCity that performs unauthenticated remote code execution via agent polling protocol deserialization,…

PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

Local file inclusion exploitation tool

POC for Spring Kafka Deserialization Vulnerability CVE-2023-34040

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Proof-of-concept exploit for CVE-2019-10068, a deserialization RCE in Kentico CMS, that uploads an ASP.NET webshell for authorized security testing.

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution



A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)


WP GDPR Compliance <= 1.4.2 - Remote Code Execution (exploiter)
