


Math.js Expression Parser RCE

CVE Reproduction: cve-2026-0770-langflow_rce_reproduction

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

PluckCMS 4.7.20 Zip Slip vulnerability Led to RCE

POC (RCE) -> CVE-2019-9978

Proof-of-concept exploit for CVE-2026-48908, an unauthenticated RCE in Joomla SP Page Builder via arbitrary file upload, with adaptive payload…

Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for…

CVE-2026-33017 Exploit | by infrar3d

Reproduction of cve-2025-43564-tomcat_put_rce_reproduction

Unauthenticated exploit for CVE-2026-68771, a pickle deserialization RCE in ComfyUI. Plants a crafted shard via /upload/image, triggers it through…

PoC exploit for Fastjson RCE (CVE-2026-16723) featuring automated JAR payload generation and delivery via crafted JSON, bypassing AutoType…

Unauthenticated RCE exploit for Feast registry gRPC server (CVE-2026-56121) using dill deserialization. Includes payload generation, reverse shell…


Exploit for Craft CMS pre-authentication RCE (CVE-2025-32432) chaining session poisoning with insecure deserialization to execute arbitrary commands…

Authenticated RCE exploit for Grav CMS via plugin upload, demonstrating arbitrary PHP code execution and reverse shell.

React2shell-web-scanner

Exploit code and technical analysis for CVE-2024-38063, a critical Windows TCP/IP RCE vulnerability, including CVSS metrics and exploitation details…