React2Shell (CVE-2025-55182) PoC
Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning support.
OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario (Payment Schedule) module.
Double-free in Apache httpd mod_http2 stream cleanup leading to pre-auth RCE
CVE-2018-18778 - ACME mini_httpd Arbitrary File Read
Copy fake in-memory files to disk using overlayFS
Python poc, exploit for CVE-2025-69212
CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)
Browser-based Merkle tree demo — build a tree, generate inclusion proofs, recompute the root hash by hash, and replay the RFC 6962 second-preimage and CVE-2012-2459 attacks. Real SHA-256. No backend.
React2Shell: CVE-2025-55182
Hack The Box - DevHub Machine Walkthrough (Medium Linux, CVE-2026-23744, Chisel Tunneling, Jupyter, Root Privilege Escalation)
CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels: ≤ 6.12.9
Обзор n-day уязвимости на русском языке.
CVE-2026-41940 authentication bypass vulnerability proof-of-concept
PoC for CVE-2025-56399 - Unrestricted File Upload leading to RCE in alexusmai/laravel-file-manager (≤3.3.1). Automates detection, CSRF extraction, and File Upload
DirtyClone - local privilege escalation (LPE) proof-of-concept targeting a kernel/XFRM-related vulnerability described in the source as CVE-2026-43503
OpenSTAManager-RCE-Exploit-CVE-2026-38751
Automated PoC for CVE-2025-69212 - OpenSTAManager <=2.9.8 authenticated RCE