
CVE-2024-9441
Exploit for CVE-2024-9441: Remote Code Execution via improper input sanitization in PHP forgot-password functionality. Uploads a malicious script and…

Exploit for CVE-2024-9441: Remote Code Execution via improper input sanitization in PHP forgot-password functionality. Uploads a malicious script and…

CVE-2020-26217 && XStream RCE

[CVE-2020-0688] Microsoft Exchange Server Fixed Cryptographic Key Remote Code Execution (RCE)

CVE-2024-0195 Improper Control of Generation of Code ('Code Injection')

Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload to RCE (CVE-2026-0740)

CVE-2025-69212 Proof-of-concept.

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload

CVE-2020-26217 XStream RCE POC

Automated PoC script for CVE-2023-36845, exploiting a PHP flaw in Juniper Junos OS J-Web to remotely modify PHPRC and achieve code injection on…

A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)

Proof-of-concept exploit for CVE-2022-42899, demonstrating remote code execution in Apache Commons Text 1.5-1.9 via StringSubstitutor interpolation…

CurveBall CVE exploitation

Proof-of-concept for authenticated remote code execution in ClipBucket via PHP code injection in update_launch.php. Includes web shell deployment and…

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

Jackson Deserialization CVE-2017-7525 PoC

Proof-of-concept exploit for CVE-2026-7393: unrestricted file upload in Pizzafy Ecommerce System 1.0 allowing authenticated administrators to upload…