
Spring4shell-CVE-2022-22965-POC
Another spring4shell (Spring core RCE) POC

Another spring4shell (Spring core RCE) POC

SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

Unauthenticated remote code execution exploit targeting insecure YAML deserialization in LLM connection checks; supports arbitrary command execution…

Reproducer for CVE-2026-46585: Apache Camel camel-lucene QUERY header injection enabling authorization bypass / index data exfiltration (fixed in…

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)

CVE-2026-64638 (XSS2shell) POC.

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

CVE-2026-40791: Unauthenticated stored XSS in WP Time Slots Booking Form <= 1.2.46

(CVE-2017-5638) XworkStruts RCE Vuln test script

CVE-2021-46364: YAML Deserialization in Magnolia CMS

Technical report about a critical vulnerability in Xiaomi (CVE-2024-45352)

CWE-287: Improper Authentication in parse-community parse-server

Exploit for CVE-2020-5902 targeting F5 BIG-IP RCE via path traversal and JDBC deserialization, enabling command execution, file read/write, and…

An exploit for CVE-2017-5638