
CVE-2024-6366
Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

Automated scanner and exploit for CVE-2026-27384, an unauthenticated RCE in W3 Total Cache via mfunc/eval() injection. Features auto-detection, 48…

Proof-of-concept exploit for CVE-2021-43503, a Laravel deserialization RCE vulnerability. Includes PHP POP chain generation and HTTP-based payload…

Proof-of-concept exploit for CVE-2024-31982: Java Server-Side Template Injection (SSTI) leading to remote code execution via Groovy payload injection.

Simple payload builder

A tool for generating fake code signing certificates or signing real ones

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)

Proof-of-concept exploit for CVE-2019-10758, demonstrating remote code execution in mongo-express via crafted document injection. Includes curl and…

RCE on Kibana versions before 5.6.15 and 6.6.0 in the Timelion visualizer

Proof-of-concept exploit for CVE-2021-26084, an OGNL injection vulnerability in Confluence Server and Data Center, demonstrating unauthenticated…

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

CVE-2022-22947批量

PoC Exploit for VM2 Sandbox Escape Vulnerability

Proof-of-concept exploit for CVE-2018-19127 in phpcms 2008, demonstrating remote code execution via crafted template parameter leading to webshell…

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.4