
multiparty-CVE-2026-8161
Proof-of-concept exploit for CVE-2026-8161, a denial-of-service vulnerability in multiparty multipart parser, demonstrating prototype pollution…

Proof-of-concept exploit for CVE-2026-8161, a denial-of-service vulnerability in multiparty multipart parser, demonstrating prototype pollution…

Exploit script for CVE-2025-49844, a use-after-free vulnerability in Redis Lua parser, enabling remote code execution on vulnerable Redis servers.

Proof-of-concept exploit for CVE-2016-4437, an Apache Struts2 remote code execution vulnerability. Demonstrates exploitation of the Jakarta Multipart…

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

Self-contained demo for GitLab RCE exploiting two Ruby memory corruption bugs in the Oj parser through notebook diff rendering.

CVE-2026-64638 (XSS2shell) POC.

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

Another spring4shell (Spring core RCE) POC

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script

(CVE-2017-5638) XworkStruts RCE Vuln test script

Proof-of-concept exploit for CVE-2024-23897 enabling remote code execution on Jenkins instances via vulnerable args4j command-line parser. Written in…

Technical report about a critical vulnerability in Xiaomi (CVE-2024-45352)

CVE-2021-46364: YAML Deserialization in Magnolia CMS

Exploit for CVE-2020-5902 targeting F5 BIG-IP RCE via path traversal and JDBC deserialization, enabling command execution, file read/write, and…

Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE)

CVE-2017-8759 - A vulnerability in the SOAP WDSL parser.

An exploit for CVE-2017-5638