
CVE-2026-54350-Budibase-NoSQL-Injection
PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

Finding Java/C# gadget chains with CodeQL

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

CVE-2022-39197 RCE POC

MindsDB Path Traversal to RCE PoC

OpenClaw Authentication Token Exfiltration

Python exploit for CVE-2025-49132, enabling unauthenticated remote code execution on Pterodactyl Panel via crafted locale and namespace parameters.

The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.

Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE…