
Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE
CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of…

CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of…

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

Proof-of-concept exploit for CVE-2025-69212 that authenticates to a URL with admin credentials and triggers a reverse shell to the specified attacker…

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

Exploit for Fastjson RCE (CVE-2026-16723) targeting versions 1.2.68 to 1.2.83. Generates JAR and JSON payloads, hosts HTTP server, and establishes…

POC for CVE-2026-23744 for a python revshell

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

Python exploit for unauthenticated remote code execution in SharePoint Server via BinaryFormatter deserialization of SecurityContextToken cookies.

Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing

PoC demonstrating quadratic DoS in Elixir html_sanitize_ex via crafted HTML; includes timing benchmarks, remote exploitation curl, and verification…

Automated proof-of-concept exploit for the Metabase H2 unsafe deserialization vulnerability, executing arbitrary commands on target servers with…

Repository of proof-of-concept exploit files for CVE-2026-42588, a Spring RCE vulnerability, including XML payloads for exploitation testing.

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

PoC for CVE-2025-3248: unauthenticated RCE in Langflow < 1.3.0 via /api/v1/validate/code.

Behavior-first WordPress CVE-2026-64638 scanner using benign login probes; classifies sanitizer behavior and generates alert-only PoCs for authorized…

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.