
CVE-2021-27850_POC
A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution.

A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution.

This is a proof of concept for CVE-2023-24610

PoC for CVE-2025-3248: unauthenticated RCE in Langflow < 1.3.0 via /api/v1/validate/code.

Proof-of-concept exploit for CVE-2025-24813, achieving remote code execution on Apache Tomcat via session deserialization and partial PUT requests.

Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")

Proof-of-concept exploit for CVE-2022-30190 (Follina) that generates malicious Word documents with remote payload hosting for calc.exe execution.

Proof of Concept script to exploit the authenticated SSTI+RCE in Grav CMS (CVE-2024-28116)

Proof-of-concept exploit for CVE-2024-36401 enabling remote code execution via HTTP requests with reverse shell payload generation and Base64…

Nuclei template providing a proof-of-concept for CVE-2024-4577, a PHP CGI argument injection vulnerability, enabling automated detection and testing.

Proof of concept exploit for Ivanti EPM CVE-2024-13159 and others

PoC for CVE-2024-25641 Authenticated RCE on Cacti v1.2.26

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

CVE-2026-63030

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

mjml-app v3.0.4 & 3.1.0-beta RCE exploit