
CVE-2024-7029
PoC exploit for CVE-2024-7029 in AvTech devices. Scans for vulnerable targets and provides an interactive remote shell for command execution with…

PoC exploit for CVE-2024-7029 in AvTech devices. Scans for vulnerable targets and provides an interactive remote shell for command execution with…

Shell-based remote code execution exploit targeting CVE-2019-19781 in Citrix Application Delivery Controller and Citrix Gateway. Executes arbitrary…

Proof-of-concept detection tool for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520, CVE-2026-10523).…

Exploit CVE-2025-49844 Redis Lua UAF vulnerability to execute arbitrary shellcode and establish persistent backdoor access on vulnerable Redis…

Java-based exploit for CVE-2022-26134 that deploys a Behinder memory shell on vulnerable Atlassian Confluence servers for remote command execution.

Python exploit script for CVE-2019-16278, a remote command execution vulnerability in Nostromo httpd. Executes arbitrary commands on vulnerable…

Exploit for CouchDB arbitrary command execution vulnerability (CVE-2017-12636). Automates remote code execution against vulnerable CouchDB instances.

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE-2024-47823, CVE-2025-54068,…

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

Python proof-of-concept for Apache Spark Shell Command Injection (CVE-2022-33891), featuring sleep-based detection, interactive command execution,…

Proof-of-concept exploit for CVE-2026-23744, an unauthenticated RCE in MCPJam Inspector. Provides reverse shell and command execution via a…

Proof-of-concept exploit for CVE-2026-20253, enabling unauthenticated remote code execution on vulnerable Splunk Enterprise instances via file write…

Interactive command-line shell for exploiting Apache Struts CVE-2017-5638. Automates HTTP/HTTPS exploitation with real-time shell interaction on…

Proof-of-concept demonstrating OS command injection in Warp's legacy SSH background command handling (CVE-2026-48732). Includes local simulation of…

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while…

Authenticated RCE exploit for NocoBase workflow engine sandbox escape (CVE-2026-34156). Executes arbitrary system commands via crafted workflow…

Python exploit for Atlassian Confluence CVE-2022-26134 OGNL injection vulnerability enabling unauthenticated remote code execution on vulnerable…