
CVE-2026-73678-PoC
CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM

CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM

Proof-of-concept exploit for Apache Struts S2-072 (CVE-2026-73633), demonstrating CPU and memory exhaustion by sending crafted JSON requests to the…

Proof-of-concept exploit for FreePBX Endpoint module CVE-2025-5781: chains unauthenticated SQL injection with database manipulation and scheduled…

mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut

CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini…





PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…


Proof-of-concept exploit for CVE-2026-72898 in Metabase, with technical reproduction steps and usage guidance for validating the vulnerability during…

WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

MCP environment-variable blocklist bypass leads to unauthenticated RCE in Flowise 3.1.1

Exploit code for CVE-2026-55040, it can create auth header for any validate account.


PoC exploit for CVE-2022-35914 — GLPI v.10.0.2 htmLawed command injection, command execution, and reverse shell support.