
CVEs
Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs

Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs

Awesome information for WebSockets security research


Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original…


Resources and PoCs

PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain



Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750

Home Owners Collection Management System 1.0 - Reflected XSS

Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.

CVE-2026-48907

PoC, Hunting React2Shell about CVE-2025-55182

CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit

ToolShell scanner - CVE-2025-53770 and detection information