
CVE-2018-19207
WP GDPR Compliance <= 1.4.2 - Remote Code Execution (exploiter)

WP GDPR Compliance <= 1.4.2 - Remote Code Execution (exploiter)

Old exploit for Issue 1076708


Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

CVE-2022-29359 - School Application System Stored Cross-Site Scripting

Python script to inject existing Android applications with a Meterpreter payload.


RCE exploit for dompdf

That repository contains my updates to the well know java deserialization exploitation tool ysoserial.

I'll submit the poc after blackhat

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.