
Limelighter
A tool for generating fake code signing certificates or signing real ones

A tool for generating fake code signing certificates or signing real ones

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)

Proof-of-concept exploit for CVE-2019-10758, demonstrating remote code execution in mongo-express via crafted document injection. Includes curl and…

CVE-2022-22947批量

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer

Proof-of-concept exploit for CVE-2021-26084, an OGNL injection vulnerability in Confluence Server and Data Center, demonstrating unauthenticated…

PoC Exploit for VM2 Sandbox Escape Vulnerability

Proof-of-concept exploit for CVE-2018-19127 in phpcms 2008, demonstrating remote code execution via crafted template parameter leading to webshell…

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.4

CVE-2025-31324, SAP Exploit

[CVE-2017-9822] DotNetNuke Cookie Deserialization Remote Code Execution (RCE)

CVE 2025 27237 Zabbix LPE proof of concept.

Proof-of-concept exploit for CVE-2024-34716, a PNG-driven XSS to RCE chain in PrestaShop 8.1.5, enabling remote code execution via crafted image…

(Wordpress) Ninja Forms File Uploads Extension <= 3.0.22 – Unauthenticated Arbitrary File Upload

Basic code for creating the Alibaba FastJson + Spring gadget chain, as used to exploit Apache Dubbo in CVE-2019-17564 - more information available at…