
CVE-2025-54123-Poc
CVE-2025-54123 Hoverfly Authenticated Middleware Command Injection RCE

CVE-2025-54123 Hoverfly Authenticated Middleware Command Injection RCE

Go-based proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components. Features vulnerability checking, command execution, memory…

Python proof-of-concept for CVE-2026-67401, an authenticated SQL injection in cPanel EmailTrack that allows arbitrary file write as root via SQLite…

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

Authenticated Stored XSS in LifeRay 7.2.0 GA1 via MyAccountPortlet executed by Search Results

[PoC] Privilege escalation & code execution via LFI in PwnDoC

Python proof-of-concept exploit for Bludit 3.9.2 remote code execution via directory traversal in image upload, enabling PHP payload injection to…

Technical analysis and proof of concept for CVE-2026-59827, a critical unsafe Java deserialization vulnerability in Metabase leading to remote code…

CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

CVE-2022-31814 Exploitation Toolkit.

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

Proof-of-concept exploit for CVE-2017-0108, a remote code execution vulnerability in Microsoft Windows Graphics Component, triggered via crafted…

Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account

Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.

Python exploit for CVE-2025-57819 targeting FreePBX via unauthenticated SQL injection to achieve remote code execution with automatic reverse shell…