
CVE-2020-11651-Poc
Proof-of-concept exploit for CVE-2020-11651, a critical remote code execution vulnerability in SaltStack, enabling unauthenticated command execution…

Proof-of-concept exploit for CVE-2020-11651, a critical remote code execution vulnerability in SaltStack, enabling unauthenticated command execution…

POC for CVE-2026-41179

C-based proof-of-concept exploit for CVE-2025-53024, demonstrating a specific vulnerability with a targeted payload for security testing and…

Proof-of-concept exploit for CVE-2025-24813, an unauthenticated RCE in Apache Tomcat via partial PUT and deserialization. Includes Docker lab for…

Reproducer for CVE-2026-27172: Apache Camel camel-consul ConsulRegistry Java deserialization (RCE)

CVE Reproduction: cve-2025-61882-oracle_ebs_rce_reproduction

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction

WordPress Core Pre-Auth RCE via REST Batch Route Confusion + SQLi (CVE-2026-63030 + CVE-2026-60137)

Reproduction of cve-2024-1708-connectwise_rce_reproduction

Proof-of-concept exploit for CVE-2024-21182, an unauthenticated JNDI injection leading to remote code execution in Oracle WebLogic Server via T3/IIOP…

Frontend File Manager Plugin (WordPress) <= 23.6 - Unauthenticated Arbitrary File Deletion to RCE

oPanel Authanticated Remote Code Execution via 'advenced/curl' Component

CVE-2026-21858 + CVE-2025-68613 — n8n unauthenticated file read to RCE exploit

Proof-of-concept exploit for CVE-2025-24893, an unauthenticated remote code execution vulnerability in XWiki via unsafe Groovy expression handling in…

CVE-2017-9841 is a Remote Code Execution (RCE) vulnerability in the PHPUnit library affecting versions prior to 5.6.3 and 6.x prior to 6.4.2.

PoC for CVE-2019-16941

CVE-2026-12415-or-CVE-2026-12416.py

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC