
Limelighter
A tool for generating fake code signing certificates or signing real ones

A tool for generating fake code signing certificates or signing real ones

Python-based exploit for CVE-2021-3129 enabling remote code execution on vulnerable Laravel applications with automatic log path detection and…

Authenticated DuckDB SQL injection exploit for Grafana enabling arbitrary file read and remote code execution on vulnerable versions.

Proof-of-concept exploit for CVE-2019-10758, demonstrating remote code execution in mongo-express via crafted document injection. Includes curl and…

Batch vulnerability scanner and exploit tool for CVE-2022-22947 Spring Cloud Gateway RCE, supporting single-target and mass scanning with SpEL…

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer

Proof-of-concept exploit for CVE-2021-26084, an OGNL injection vulnerability in Confluence Server and Data Center, demonstrating unauthenticated…

Proof-of-concept exploit for CVE-2018-19127 in phpcms 2008, demonstrating remote code execution via crafted template parameter leading to webshell…

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.4

Proof-of-concept exploit for CVE-2025-31324, a critical SAP NetWeaver vulnerability enabling unauthenticated remote code execution via file upload to…

Proof-of-concept exploit for CVE-2017-9822, a cookie deserialization RCE in DotNetNuke 5.0.0-9.3.0. Includes payload generation via ysoserial.net and…

Proof-of-concept for CVE-2025-27237: local privilege escalation in Zabbix Agent for Windows via OpenSSL configuration file hijacking, with PoC DLLs…

Proof-of-concept exploit for CVE-2024-34716, a PNG-driven XSS to RCE chain in PrestaShop 8.1.5, enabling remote code execution via crafted image…

Java-based gadget chain generator for exploiting Apache Dubbo deserialization vulnerability (CVE-2019-17564) using FastJson and Spring Framework…

(Wordpress) Ninja Forms File Uploads Extension <= 3.0.22 – Unauthenticated Arbitrary File Upload

Python3 exploit for ISPConfig <= 3.2.11 PHP code injection (CVE-2023-46818) that authenticates as admin and executes arbitrary PHP code via…