
CVE-2024-41570-Havoc-C2-RCE
This is a Chained RCE in the Havoc C2 framework using github.com/chebuya and github.com/IncludeSecurity pocs

This is a Chained RCE in the Havoc C2 framework using github.com/chebuya and github.com/IncludeSecurity pocs

Proof-of-concept exploit for CVE-2022-40127 targeting Apache Airflow RCE via crafted run_id parameter, with automated reverse shell delivery.

Perform with massive Jenkins Reading-2-RCE

Unauthenticated RCE exploit for Langflow OSS chaining auto_login JWT bypass with validate/code exec() to achieve remote command execution and reverse…

CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE written in Rust

Go-based exploit for CVE-2022-40684 targeting Fortinet FortiGate devices. Automates authentication bypass to gain administrative access via the web…

Proof-of-concept exploit for a command injection vulnerability in VitalPBX Task Manager module, demonstrating reverse shell payload delivery via cron…

All-in-one exploit tool for CVE-2026-27966, a critical RCE in Langflow. Features mass scanning, auto-detection, payload execution, interactive shell,…

trojan CVE-2024-28085 CVE 28085

Modification of gitlab exploit anything under 13.10

teamcity-exploit-cve-2023-42793

Authenticated RCE exploit for NocoBase workflow engine sandbox escape (CVE-2026-34156). Executes arbitrary system commands via crafted workflow…

Proof-of-concept exploit for CVE-2026-23744, an unauthenticated command injection in MCP Connect leading to remote code execution and reverse shell.

Unauthenticated RCE exploit for GeoServer (CVE-2024-36401) via OGC filter XPath injection. Supports reverse shell and blind command execution with…

Demonstrates command injection vulnerabilities in RayVentory Scan Engine's rvia tool, allowing arbitrary command execution via getconfig, upload,…

Proof-of-concept exploit for CVE-2025-56015, a sandbox escape and RCE in GenieACS. Automates malicious provision creation, preset mapping, and…

Manual exploit script for CVE-2004-2687 (distccd RCE) that spawns a reverse shell via netcat without Metasploit, targeting remote hosts for…

Proof of Concept exploit for CVE-2026-46368 — authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521)