
CVE-2019-0232-EXP
Exploit for Apache Tomcat CGI Servlet command injection (CVE-2019-0232) enabling remote code execution via crafted HTTP requests on affected versions.

Exploit for Apache Tomcat CGI Servlet command injection (CVE-2019-0232) enabling remote code execution via crafted HTTP requests on affected versions.

Proof-of-concept exploit for CVE-2022-26134 in Confluence Server, using OGNL injection to execute commands via crafted HTTP requests.

Proof-of-concept exploit for CVE-2023-45158, a command injection vulnerability in web2py. Demonstrates remote code execution via crafted HTTP…

Proof-of-concept exploit for CVE-2024-23692, demonstrating command injection in HFS via crafted HTTP requests to execute system commands and retrieve…

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

Exploit CVE-2024-43468 and CVE-2025-59213 to implant a controlled backdoor into SCCM Management Point's SQL stored procedure, enabling remote SQL…

Automates CVE-2024-23692 exploitation against unpatched Rejetto HFS with an in-memory PowerShell reverse shell, HTTP payload staging, and AV/EDR…

C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This…

Proof-of-concept exploit for CVE-2022-30525 enabling unauthenticated remote command injection on Zyxel firewalls via HTTP POST requests to the…

Python-based proof-of-concept exploit for ZeroShell 3.9.0 remote command injection via mishandled HTTP parameters, enabling unauthenticated OS…

Proof-of-concept exploit for CVE-2024-29973, a remote command injection in Zyxel NAS devices, demonstrating arbitrary command execution via crafted…

CVE-2021-41773 | Apache HTTP Server 2.4.49 is vulnerable to Path Traversal and Remote Code execution attacks

Python exploit for CVE-2022-26134 targeting Confluence Server RCE with command execution via HTTP request.

Python script to detect CVE-2022-30525 OS command injection vulnerability in Zyxel USG FLEX devices by sending crafted HTTP requests and analyzing…

Java GUI tool for exploiting CVE-2026-21962, an unauthenticated RCE in Oracle WebLogic Proxy Plug-In, enabling multi-target command execution via…

Python exploit for CVE-2026-23744 in MCPJam Inspector 1.4.2, enabling remote code execution via reverse shell on target HTTP servers.

Unauthenticated OS command injection exploit for InSAT MasterSCADA BUK-TS MMadmServ web interface. Delivers reverse shell with root privileges via…

Proof-of-concept exploit for CVE-2023-27216, a command injection vulnerability in D-Link DSL-3782 routers, enabling remote code execution via crafted…