
wp2shell
PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

Educational analysis and proof-of-concept exploit for CVE-2025-3248, a critical unauthenticated code injection vulnerability in Langflow, including…


FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

Self-contained Docker lab that reproduces CVE-2025-24893, an unauthenticated SSTI-to-RCE in XWiki SolrSearch, and compares vulnerable vs patched…

Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for…

Technical analysis of CVE-2025-55182 (React2Shell), covering vulnerability mechanics, root cause, controlled PoC testing, impact, and mitigation…

Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)



Interactive visualization of the React2Shell (CVE-2025-55182) RCE vulnerability with narrated animations for three audiences: Expert, Practitioner,…


wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

CVE-2021-20717-EC-CUBE-XSS

The Online Diagnostic Lab Management System has a security problem called Cross-Site Scripting (XSS) in the Borrower section.

CVE-2023-38646

CVE-2025-33053 Checker and PoC