
POC_react2shell_CVE-2025-55182
Exploit for CVE-2025-55182 targeting Next.js React Server Components via prototype pollution, enabling remote code execution with command execution…

Exploit for CVE-2025-55182 targeting Next.js React Server Components via prototype pollution, enabling remote code execution with command execution…

Python implementation of CVE-2023-43208 Mirth Connect RCE (Unauth XStream)

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original…

A bash script demonstrating the manual exploitation of CVE-2016-10204 against a target endpoint, leading to upload of a php webshell.

Reproducible exploits for: CVE-2016-1240 CVE-2008-2938 CVE-2014-2064 CVE-2014-1904

Step-by-step exploit harness and proof-of-concept for CVE-2026-25526 in Jinjava, demonstrating file read, file creation, and info disclosure with…

Proof of Concept exploit for the Joomla 3.7.0 com_fields SQL injection vulnerability (CVE-2017-8917), demonstrating detection, enumeration, and data…

Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

Technical advisory and analysis of CVE-2025-14598, a critical unauthenticated SQL injection in BET e-Portal enabling database manipulation and…

Proof-of-concept exploit for CVE-2026-1560, an authenticated remote code execution vulnerability in Lazy Blocks WordPress plugin, allowing…

Cisco is aware of a potential vulnerability. Cisco is currently investigating and will update these details as appropriate as more…

Exploit for Rocket.Chat 3.12.1 RCE via pre-auth NoSQL injection, leaking admin TOTP secret and password reset token to achieve remote code execution…

A critical vulnerability in React Server Components affecting React 19 (CVE-2025-55182) and frameworks that use it like Next.js (CVE-2025-66478).

POC-Django JSONField/HStoreField SQL Injection Vulnerability (CVE-2019-14234)

Proof-of-concept exploit for authenticated remote code execution in pgAdmin4 (CVE-2025-2945) via SQL Editor abuse. Designed for authorized security…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Apache-HTTP-Server-2.4.50-RCE This tool is designed to test Apache servers for the CVE-2021-41773 / CVE-2021-42013 vulnerability. It is intended for…

CVE-2025-29927 Exploit Checker