
cve-2022-36804
Python exploit for CVE-2022-36804, enabling remote command execution and file transfer on vulnerable Bitbucket Server/Data Center via crafted archive…

Python exploit for CVE-2022-36804, enabling remote command execution and file transfer on vulnerable Bitbucket Server/Data Center via crafted archive…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

DO NOT RUN THIS.

Python proof-of-concept for CVE-2025-54123, demonstrating command injection to RCE in Hoverfly middleware API with credential or token-based…

CVE-2026-6279

Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

VsFTPd 2.3.4 Backdoor Command Execution

Generates JavaScript payloads to exploit CVE-2024-28397 Js2Py sandbox escape, enabling remote command execution and reverse shells via Python…

A script for exploiting a vulnerability in PyTorch with subsequent RCE in library versions < 2.6.0

Manual exploit script for CVE-2004-2687 (distccd RCE) that spawns a reverse shell via netcat without Metasploit, targeting remote hosts for…

Python exploit script for CVE-2025-54123 targeting Hoverfly RCE with command execution and reverse shell capabilities for authorized security testing.

Remote privilege escalation exploit for CVE-2018-1049 targeting VyOS via SSH-based command injection in a sudo-permitted Perl script, granting root…

Mass Exploit for CVE-2025-29306

Exploit for the CVE-2025-37164

Bash exploit for CVE-2025-24893, unauthenticated RCE in XWiki Platform, using template injection in the SolrSearch macro to execute arbitrary system…

Proof-of-concept exploit for CVE-2025-1338, a command injection vulnerability in NUUO Camera, with multi-threaded scanning and result output.

Cobalt Strike Aggressor script that weaponizes LNK and Library-MS files to trigger SMB NTLMv2 hash disclosure, including CVE-2025-24054 bypass, for…