
CVE-2015-7501
Educational lab for understanding Java deserialization vulnerabilities with PoC exploits for JBoss CVEs, gadget chain analysis, and a vulnerable HTTP…

Educational lab for understanding Java deserialization vulnerabilities with PoC exploits for JBoss CVEs, gadget chain analysis, and a vulnerable HTTP…

Creating a vulnerable environment and the PoC

PoC exploit scanner for CVE-2024-5522 in WordPress. Scans target URLs with custom payloads to identify vulnerable sites, outputting color-coded…

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Heap-based buffer overflow exploit for CVE-2021-3156 in sudo, offering local privilege escalation to root on vulnerable Linux systems.

Strapi Framework Vulnerable to Remote Code Execution

Exploit CVE-2025-49844 Redis Lua UAF vulnerability to execute arbitrary shellcode and establish persistent backdoor access on vulnerable Redis…

Simulated macOS/iOS XPC service vulnerable to NSKeyedUnarchiver deserialization, plus exploit demonstration and crafted plist payload for RCE via…

PoC for CVE-2026-9998: RCE via insecure Python pickle deserialization in a blockchain oracle, with vulnerable node simulation and exploit script.

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), a critical RCE vulnerability in React Server Components via unsafe deserialization.…

Proof-of-concept exploit for CVE-2024-6387 targeting vulnerable OpenSSH servers via heap manipulation and race condition to achieve remote code…

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

This vulnerability allows an unauthenticated attacker to remotely execute arbitrary code on a vulnerable Confluence server. The vulnerability exists…

Exploit tool for CVE-2018-15133, a Laravel unserialize RCE, with multiprocessing support for scanning and exploiting vulnerable endpoints.

Proof-of-concept exploit for CVE-2026-20253, enabling unauthenticated remote code execution on vulnerable Splunk Enterprise instances via file write…

Educational proof-of-concept demonstrating CVE-2026-31431 with a vulnerable target application, demonstration payload, and shellcode extraction…

Proof-of-concept exploit for Next.js CVE-2025-66478, demonstrating RCE via insecure deserialization and prototype pollution in Server Actions.…

Proof-of-concept exploit for CVE-2022-1329, a remote code execution vulnerability in WordPress Elementor 3.6.0-3.6.2. Includes Docker-based…