
CVE-2025-64512-Polyglot-PoC
A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

CVE-2023-30990 exploits

Authenticated Stored XSS in LifeRay 7.2.0 GA1 via MyAccountPortlet executed by Search Results

A wrapper for MSFvenom that allows for easy generation of payloads

CVE-2026-20251 — Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) | ReactiveZero Security Research

A go-exploit for Apache ActiveMQ CVE-2023-46604

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning…

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

Crater <=6.0.6, CVE-2023-46865 Post-Auth RCE (Superadmin)


Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal





Handlebars.js AST Injection Remote Code Execution Vulnerability
