
CVE-2024-30270-PoC
The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

Web Application Exploit Development

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Server-Side Template Injection Exploit


Proof-of-concept exploit for CVE-2019-10068, a deserialization RCE in Kentico CMS, that uploads an ASP.NET webshell for authorized security testing.

Local file inclusion exploitation tool

Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE


POC for Spring Kafka Deserialization Vulnerability CVE-2023-34040

Exploit code for CVE-2016-9066

fastjson-1.2.58-rce with h2 database

PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

Magento ver. 2.4.6 - XSLT Server Side Injection


Proof-of-concept exploit for JetBrains TeamCity that performs unauthenticated remote code execution via agent polling protocol deserialization,…

Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit

Research into CVE-2022-41853: Using static functions to obtian RCE via Java Deserialization & Remote Codebase Attack