
webapp-exploits
Web Application Exploit Development

Web Application Exploit Development

CVE-2026-63077 — Unauthenticated Remote Code Execution in JetBrains TeamCity via agent polling protocol deserialization. CVSS 9.8 CRITICAL. Mass…

Exploit code for CVE-2016-9066

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE


POC for Spring Kafka Deserialization Vulnerability CVE-2023-34040

fastjson-1.2.58-rce with h2 database

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

Proof-of-concept exploit for CVE-2025-14174, a use-after-free in Chrome's V8 engine. Includes JavaScript PoC and HTML embed for identifying the…

Magento ver. 2.4.6 - XSLT Server Side Injection

Exploit chain for CVE-2019-9791 & CVE-2019-11708 against firefox 65.0 on windows 64bit

Proof-of-concept script that demonstrates bypassing macOS Gatekeeper, notarization, and XProtect checks by exploiting CVE-2021-30853, allowing…

Research into CVE-2022-41853: Using static functions to obtian RCE via Java Deserialization & Remote Codebase Attack

Proof-of-concept exploit for CVE-2026-33229, an XWiki RCE via Apache Velocity sandbox bypass, with technical details and a working payload.

PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

JavaScript-based exploit for Chrome V8 vulnerability CVE-2020-6468, with a d8 shell script and an HTML-based Chrome target.