
cve-2026-63030_60137-wordpress_rce_reproduction
CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction

CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction

Full-chain RCE exploit for CVE-2025-2783, a Chromium Ipcz sandbox escape vulnerability. Implements thread hijacking, V8 hooks, and shellcode…

CVE Reproduction: cve-2024-0012_9474-panos_authbypass_reproduction

This repository contains a proof-of-concept (PoC) exploit for CVE-2026-38751, affecting OpenSTAManager ≤ 2.10. The vulnerability allows an…

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning…

CVE Reproduction: cve-2025-55182-react2shell_reproduction

Exploit for CVE-2025-64512 to get a reverse shell.

Proof-of-concept exploit for CVE-2026-20253, enabling unauthenticated remote code execution on vulnerable Splunk Enterprise instances via file write…

CVE-2026-53767 + CVE-2026-53768 - Authenticated RCE in Chyrp Lite ≤ 2026.01 via uploads_path blocklist bypass and missing extension validation

PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

PluckCMS 4.7.20 Zip Slip vulnerability Led to RCE

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

CVE-2026-56121 — Feast <0.63.0 unauthenticated RCE via gRPC registry dill.loads of OnDemandFeatureView UDF (pre-auth). Lab + PoC, verified e2e.

Single click Remote Code Execution exploit targeting Gajim on devices with KDE Plasma.

CVE-2024-49375、CVE-2021-42556、CVE-2021-41127

C++ exploit for unauthenticated remote code execution on CUPS via CVE-2024-47176 chain.

Unauthenticated SQL injection in FreePBX Endpoint Manager (CVE-2025-57819) that injects a cron-scheduled PHP webshell for remote code execution.

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate