
CVE-2026-48017
Remote Code Execution in DbGate via functionName injection in the loadReader endpoint — CVSS 8.8

Remote Code Execution in DbGate via functionName injection in the loadReader endpoint — CVSS 8.8

Mender Server - Authenticated Path Traversal to RCE

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

CVE-2018-9276 — PRTG Network Monitor < 18.2.39 Authenticated RCE. For educational purposes and authorized penetration testing only.

Windows POC for CVE-2021-34427 affecting Birt Viewer

CVE-2012-1823 - PHP CGI Argument Injection Remote Code Execution (RCE)

PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

Repo contains the PoC and steps to reproduce cve 2023-38646

aaPanel WebSocket CSRF Bypass leading to RCE (Incomplete fix for CVE-2021-37840)

Exploit script for Apache OFBiz CVE-2020-9496 unsafe deserialization vulnerability, enabling remote code execution via crafted XML-RPC requests with…

Proof of concept for CVE-2025-39866 (UAF and race condition)

Python RCE exploit for Sendmail with ClamAV-Milter <0.91.2 (CVE-2007-4560). Remote root command injection via SMTP RCPT TO headers.

Go Proof of Concept (PoC) exploit for Flowise CustomMCP Remote Code Execution (RCE) CVE-2025-59528

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

Python exploit for CVE-2025-57819 targeting FreePBX via unauthenticated SQL injection to achieve remote code execution with automatic reverse shell…

O F5 BIG-IP é uma plataforma de entrega e segurança de aplicações amplamente utilizada em ambientes corporativos. A CVE-2020-5902 é uma…

Reproducer for CVE-2026-33453: Apache Camel camel-coap header injection to RCE via camel-exec