
CVE-2026-60004-POC
CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning…

CVE 2025 27237 Zabbix LPE proof of concept.

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…

PoC for CVE-2023-2579

Proof-of-concept exploit for Moodle CVE-2024-43425, enabling authenticated RCE via crafted calculated questions. Automates login, token extraction,…

Exploit for CVE-2025-54123, an authenticated OS command injection in Hoverfly's middleware API, providing check-only, single-command, interactive…

💥 Python Exploit for CVE-2025-49113 | Roundcube Webmail RCE via PHP Object Injection

PoC exploit for CVE-2020-11800, a command injection in Zabbix Server via malicious agent auto-registration, with Python-based payload delivery and…

Proof-of-concept exploit for CVE-2025-69212: OS command injection in OpenSTAManager's P7M file processing, enabling authenticated remote code…

Proof-of-concept exploit for CVE-2026-37748, an unrestricted file upload vulnerability in Visitor Management System 1.0 leading to remote code…

Python PoC for CVE-2025-60787, authenticated OS command injection RCE in motionEye <= 0.43.1b4 via unsanitized image_file_name config

Write-up and proof of concepts for CVE-2021-30862, 1-click RCE bug in iOS iTunes U

Exploit for CVE-2025-3054 targeting arbitrary file upload in WP User Frontend Pro plugin, enabling authenticated attackers to achieve remote code…

Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the…

SecurityTube Linux Assembly Expert x86 Exam

Proof-of-concept exploit for CVE-2026-33017 demonstrating unauthenticated remote code execution in Langflow via malicious CustomComponent injection…