
CVE-2026-77991
Proof-of-concept and lab pack for CVE-2026-77991, a privileged PHP file-write RCE in Joomla Event Manager through 5.0.0, with Docker lab and witness…

Proof-of-concept and lab pack for CVE-2026-77991, a privileged PHP file-write RCE in Joomla Event Manager through 5.0.0, with Docker lab and witness…

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Proof-of-concept exploit for CVE-2026-75430, achieving unauthenticated remote code execution on PowerJob Worker via arbitrary JAR loading through the…

Vulnerability in GNU InetUtils telnetd Enables Remote Root Access

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

Log4Shell CVE-2021-44228 Demo

PHP shells that work on Linux OS, macOS, and Windows OS.

PoC de RCE en PostgreSQL — CVE-2025-8714


A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.

Exploit script for Apache HTTP Server 2.4.49/2.4.50 path traversal and remote code execution (CVE-2021-41773). Includes Docker-based reproduction…

Another spring4shell (Spring core RCE) POC

SambaCry exploit and vulnerable container (CVE-2017-7494)

CVE-2020-28502 node-XMLHttpRequest RCE

Spring4Shell - CVE-2022-22965

Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…

PHPMailer < 5.2.18 Remote Code Execution

Exploit for the PHP 8.1.0-dev backdoor vulnerability (CVE-2021-21707)