
sk-cve-2026-26030-lab
Ethical, network-isolated Docker lab reproducing CVE-2026-26030 — Semantic Kernel in-memory vector store filter eval() RCE (patched in 1.39.4)

Ethical, network-isolated Docker lab reproducing CVE-2026-26030 — Semantic Kernel in-memory vector store filter eval() RCE (patched in 1.39.4)

Builds a shell.so reverse shell payload for CVE-2025-1974 (IngressNightmare) using Alpine Linux in Docker, with hardcoded IP and port configuration.


Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

Step-by-step walkthrough of CVE-2017-18349 Fastjson deserialization RCE exploitation, covering attack surface identification, fingerprinting, JNDI…

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…

PoC exploit for Angular Expressions sandbox escape (CVE-2024-54152) achieving RCE via malicious expression. Includes Docker environment and payload…

Proof-of-concept for CVE-2023-32571, demonstrating remote code execution via Dynamic Linq injection in ASP.NET applications. Includes payloads and a…

Scanner and exploit toolkit for CVE-2025-55182, a critical pre-auth RCE in React Server Components. Includes detection, interactive shell, Docker…

Proof-of-concept exploit for CVE-2025-24813, an unauthenticated RCE in Apache Tomcat via partial PUT and deserialization. Includes Docker lab for…

Proof-of-concept exploit for CVE-2024-21182, an unauthenticated JNDI injection leading to remote code execution in Oracle WebLogic Server via T3/IIOP…

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), demonstrating remote code execution in React Server Components through crafted Next-Action…

Proof-of-concept exploit for CVE-2026-54806: unauthenticated PHP object injection in WP Activity Log plugin enabling blind RCE via User-Agent header.…

PoC exploit for an unauthenticated RCE in Langflow <=1.8.1, including source-level root cause analysis, AST-aware reverse shell payload, Docker lab,…

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Proof-of-concept exploit for CVE-2022-22965 in Payara/Glassfish, demonstrating arbitrary file download via web root manipulation. Includes Docker…

CVE-2019-13132 — libzmq CURVE INITIATE stack overflow → RCE. Working exploit + Docker lab.