

patched to work

upsmon: remote OS command injection (RCE) via attacker-controlled ups.alarm in NOTIFYCMD execution

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending…

Python poc, exploit for CVE-2025-69212

GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint…

Proof of Concept (PoC) for the TP-Link DHCP Option 66 Unauthenticated RCE (CVE-2026-11834)


CVE-2025-32433 Erlang/OTP SSH RCE Exploit SSH远程代码执行漏洞EXP


Covert C2 framework using QR codes for indirect command execution and result retrieval via HTTP/S, designed for stealthy penetration testing and red…

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

PoC for Unauthenticated RCE in FortiSandbox via CVE-2026-39808

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.


The DCERPC only printerbug.py version