
CVE-2026-60004-Gitea-RCE-PoC
🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC

🫖 Direct single-target Gitea CVE-2026-60004 RCE validation PoC

Proof-of-concept exploit for CVE-2025-59287, a remote code execution vulnerability in Microsoft WSUS via unsafe deserialization. Sends crafted SOAP…

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

Proof-of-concept exploit for CVE-2026-0766, a remote code execution vulnerability in OpenWebUI via tool code injection. Includes command execution,…

Exploit tool for CVE-2026-22785, a critical code injection in orval < 7.18.0. Provides shell command execution and file scanning to demonstrate the…

wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137

CVE-2026-39987 for marimo 0.20.4 PoC

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization

Proof of Concept (POC) for the CVE-2025-25296 vulnerability affecting Label Studio versions prior to 1.16.0

Java deserialization vulnerability exploitation tool with payload generators for multiple marshallers (Jackson, XStream, SnakeYAML) and JNDI…

PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange…

Automated man-in-the-middle attack tool.

CLI wrapper for CVE-2025-64512 PoC generating malicious PDF and pickle.gz payloads to exploit insecure deserialization in pdfminer.six, enabling…

Detects vulnerable Cisco Meeting Server configurations (CVE-2018-15446) by enumerating active conference IDs and testing weak passcodes for…

Gogs service Exploit and get the root user

The tool helps in quickly identifying vulnerabilities by examining a comprehensive list of potential paths on a website, making it useful for…

Go-based exploit for CVE-2021-29447 targeting WordPress 5.6.2 with PHP 8. Generates a malicious .wav payload to retrieve arbitrary files from the…