
CVE-2024-41662
Markdown XSS leads to RCE in VNote version <=3.18.1

Markdown XSS leads to RCE in VNote version <=3.18.1

(CVE-2017-10271)Java反序列化漏洞

Analysis of the Reproduction of CVE-2025-30208 Series Vulnerabilities

Debug and proof-of-concept code for CVE-2022-41966, demonstrating exploitation of the XStream deserialization vulnerability in Java.

We've set up an environment to test CVE-2025-57833. This environment was built using AI, so it's subject to ongoing modification.

Educational proof-of-concept demonstrating SQL injection via dynamic aliases in Django's annotate() and alias() methods (CVE-2025-57833). Includes…

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

Proof-of-concept exploit for CVE-2024-51132, an XML External Entity (XXE) injection vulnerability in HAPI FHIR core libraries, enabling SSRF and…

CVE-2020-26259 &&XStream Arbitrary File Delete

Python-based checker for CVE-2020-15227 that tests Nette applications for remote code execution vulnerabilities via file_put_contents and shell_exec…

Educational lab demonstrating CVE-2020-7598 prototype pollution in minimist with a vulnerable Node.js/Express app, exploit payload, and…

Apache synapse 反序列化 CVE–2017–15708

Educational CVE-2024-12877 exploit demo for PHP Object Injection in GiveWP WordPress plugin. Includes root cause analysis, regex bypass techniques,…

Proof-of-concept exploit for CVE-2018-14667, demonstrating Java deserialization combined with EL injection to achieve remote code execution in…

CVE-2021-46364: YAML Deserialization in Magnolia CMS

Exploit Title: Node.JS - 'node-serialize' Remote Code Execution (2), Version: 0.0.4, CVE: CVE-2017-5941

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation
