
CVE-2023-46818
Python3 exploit for ISPConfig <= 3.2.11 PHP code injection (CVE-2023-46818) that authenticates as admin and executes arbitrary PHP code via…

Python3 exploit for ISPConfig <= 3.2.11 PHP code injection (CVE-2023-46818) that authenticates as admin and executes arbitrary PHP code via…

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.3

Encode and decode source code files using Unicode bidi control characters to exploit CVE-2021-42574, enabling invisible injection of malicious logic…

A PoC exploit for CVE-2024-4577 - PHP CGI Argument Injection Remote Code Execution (RCE)

CVE-2024-37032 (Probllama) PoC for Ollama ≤0.1.33: path traversal and arbitrary file write via model digest handling, leading to automated privilege…

PoC exploit for CVE-2021-26084, an OGNL injection vulnerability in Atlassian Confluence allowing unauthenticated remote code execution via crafted…

phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC (CVE-2009-1151)

All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection

PoC exploit generator for CVE-2025-64512: creates malicious pickle.gz payloads and PDFs to trigger remote code execution via pdfminer.six…

Proof-of-concept exploit for SnakeYAML CVE-2022-1471, demonstrating unsafe deserialization via crafted YAML payloads to achieve remote code execution…

Python exploit for CVE-2021-3129 (Laravel Ignition RCE) using phpggc-generated phar payloads to gain remote code execution against vulnerable Laravel…

[PoC] Privilege escalation & code execution via LFI in PwnDoC

Exploit for CVE-2024-9441: Remote Code Execution via improper input sanitization in PHP forgot-password functionality. Uploads a malicious script and…

Proof-of-concept exploit for CVE-2020-26217, demonstrating remote code execution in XStream through a crafted XML deserialization payload.

Proof-of-concept exploit for CVE-2020-0688: remote code execution on Microsoft Exchange Server via fixed cryptographic keys in ViewState…

CVE-2024-0195 Improper Control of Generation of Code ('Code Injection')

Proof-of-concept exploit for CVE-2026-0740: unauthenticated arbitrary file upload to RCE in Ninja Forms File Uploads plugin for WordPress. Includes…

Automated scanner for CVE-2026-5718, an unauthenticated file upload to RCE vulnerability in the DnD Upload CF7 WordPress plugin. Exploits non-ASCII…