
CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2
Python exploit for CVE-2026-23744 achieving remote code execution via crafted POST requests to the /api/mcp/connect endpoint in MCPJam Inspector <=…

Python exploit for CVE-2026-23744 achieving remote code execution via crafted POST requests to the /api/mcp/connect endpoint in MCPJam Inspector <=…

A PoC for CVE-2020-8816 that does not use $PATH but $PWD and globbing

Exploit for CVE-2022-30525

A minimal authenticated reverse shell framework for reaching hosts with outbound internet access.

JSP-less Java Servlets Backdoor inspired by https://www.redteam-pentesting.de/files/redteam-jboss.tar.gz

Mass Exploit for CVE-2025-29306

A oxidized version of https://github.com/nettitude/CVE-2024-20356/blob/main/CVE-2024-20356.py

Proof-of-concept demonstrating CORS to CSRF chain on Sliver's unauthenticated MCP interface, enabling silent interaction with C2 from any webpage.

Python exploit for CVE-2021-20038 targeting SonicWall SSL VPN with command-line URL/file input for remote code execution.

Proof-of-concept exploit for CVE-2025-8110, a command injection vulnerability in Gogs Git hook mechanism enabling remote code execution on…

Exploit for CVE-2023-26035 affecting ZoneMinder < 1.36.33 and < 1.37.33

Proof-of-concept exploit for a command injection vulnerability in Syrotech SY-GOPON-8OLT-L3, allowing arbitrary command execution via HTTP request…

CVE-2022-31499 Proof of Concept

Authenticated RCE exploit for ASUS ExpertWiFi and RT-AX57 Go routers via command injection in splash_page_SDN.cgi. Requires a valid login token to…

Reproduction of CVE-2022-39197, a remote code execution vulnerability in Cobalt Strike Beacon triggered by XSS via malformed usernames, with…

F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800

A OS Command Injection Vulnerability in the CGI Program of Zyxel

BIG-IP iControl REST vulnerability CVE-2022-1388 PoC