
CVE-2022-45771-Pwndoc-LFI-to-RCE
Pwndoc local file inclusion to remote code execution of Node.js code on the server

Pwndoc local file inclusion to remote code execution of Node.js code on the server

基于MemShellParty的Agent内存马二开,使其兼容主流操作系统,适用于在无回显命令执行场景下实现打入内存马。

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

MobSF Remote code execution (via CVE-2024-21633)

Exploit for CVE-2019-2890 WebLogic deserialization RCE with ysoserial integration, providing step-by-step PoC for remote code execution via T3…

geoserver CVE-2024-36401漏洞利用工具

webuploader-v-0.1.15未授权-任意文件上传

S2-061 的payload,以及对应简单的PoC/Exp

Modular Python3 attack framework for automating exploitation of SIEM platforms (Splunk, Graylog, OSSIM, QRadar, McAfee) via credential theft, payload…

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

This is a RCE bluetooth vulnerability on Android 8.0 and 9.0


POC for Spring Kafka Deserialization Vulnerability CVE-2023-34040

Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.

Trigger and exploit code for CVE-2014-4113

Apache/Alibaba Dubbo <= 2.7.3 PoC Code for CVE-2021-25641 RCE via Deserialization of Untrusted Data; Affects Versions <= 2.7.6 With Different Gadgets

基于内核漏洞CVE-2026-43499的本地提权适配,集成嵌入式 KernelSU.CVE-2026-43499+KernelSU越狱模式

This native code file aims to be complementary to the published Whatsapp GIF RCE exploit by Awakened , by calculating the system() function address…