
CVE-2019-0752
Proof-of-concept exploit for CVE-2019-0752 targeting Internet Explorer 11 on Windows 10 x64. Uses JavaScript DOM manipulation and special address…

Proof-of-concept exploit for CVE-2019-0752 targeting Internet Explorer 11 on Windows 10 x64. Uses JavaScript DOM manipulation and special address…

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

Proof-of-concept exploit for CVE-2022-1329, a remote code execution vulnerability in WordPress Elementor 3.6.0-3.6.2. Includes Docker-based…

Proof-of-concept exploit for CVE-2020-11651, a critical remote code execution vulnerability in SaltStack, enabling unauthenticated command execution…

Proof-of-Concept exploit for Apache APISIX 2.12.x RCE (CVE-2022-24112) via Lua filter_func injection. Executes arbitrary system commands on…

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

Arduino Rubber Ducky Framework

Pwndoc local file inclusion to remote code execution of Node.js code on the server

Local privilege escalation exploit for CVE-2021-1732 targeting Windows 10 and Server versions, with PoC code and affected system enumeration.

A critical Remote Code Execution (RCE) vulnerability has been identified in PluXML CMS version 5.8.22. This vulnerability allows authenticated…

Hotel Druid 3.0.3 Code Injection to Remote Code Execution

PrintNightmare - Windows Print Spooler RCE/LPE Vulnerability (CVE-2021-34527, CVE-2021-1675) proof of concept exploits

CVE-2022-41852 Proof of Concept (unofficial)

CVE-2021-26084 - Confluence Server Webwork OGNL injection

a realistic POC demonstrating the missing `hasOwnProperty` check in [email protected]

Proof-of-concept exploit for CVE-2026-25924, demonstrating administrative remote code execution in Kanboard through a missing access control check on…

Exploit on the default cache of superset by using pickle