
CVE-2026-44788
Proof-of-concept exploit for CVE-2026-44788, demonstrating vulnerability exploitation in C# for security testing and validation.

Proof-of-concept exploit for CVE-2026-44788, demonstrating vulnerability exploitation in C# for security testing and validation.

Detaped is a Python disassembler and decompiler for Duktape. The intended use is for source code review and analysis in situations where you only…

Proof-of-concept exploit for CVE-2023-29007, a Git arbitrary configuration injection vulnerability. Demonstrates exploitation on Windows systems for…

Pre-authentication remote code execution exploit for FUEL CMS 1.4.1 (CVE-2018-16763). Python-based proof-of-concept for security testing and…

WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型…

Proof-of-concept for authenticated remote code execution in ClipBucket via PHP code injection in update_launch.php. Includes web shell deployment and…

Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

Proof-of-concept for CVE-2026-29628, a stack-based buffer overflow in tinyobjloader's experimental parser, with ASan/UBSan reproduction and fix…

Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.

Proof-of-concept exploit demonstrating UMCI bypass in Internet Explorer using JScript and ActiveX to execute arbitrary binaries, targeting Windows…

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

PHP-based exploit module targeting CVE-2025-67146 and CVE-2025-67147 for automated vulnerability exploitation and security assessment.

Proof-of-concept exploit for CVE-2026-20817, demonstrating the vulnerability with a C-based implementation for security research and testing.

Proof-of-concept exploit for CVE-2025-25014: Prototype pollution in Kibana enabling arbitrary code execution via crafted HTTP requests to ML and…

Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell…

Proof-of-concept exploit for CVE-2023-27363, demonstrating a specific vulnerability with automated exploitation logic for security testing and…

Python library for local LLM-powered security analysis with Ghidra binary analysis, C/C++ vulnerability scanning, and MCP tool integration for…

Proof-of-concept exploit for CVE-2026-3888, written in C. Demonstrates vulnerability exploitation and binary-level attack techniques for security…