
EH2-PoC
A simple PoC for CVE-2022-46169 a.k.a Cacti Unauthenticated Command Injection, a vulnerability allows an unauthenticated user to execute arbitrary…

A simple PoC for CVE-2022-46169 a.k.a Cacti Unauthenticated Command Injection, a vulnerability allows an unauthenticated user to execute arbitrary…
Meterpreter auto exploit program

Proof-of-concept exploit for CVE-2023-36143 demonstrating command injection in Maxprint Maxlink 1200G v3.4.11E via the diagnostic tool web interface.

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

Samba 3.0.20

Proof-of-concept demonstrating CVE-2024-32002 remote code execution via malicious Git submodule hook, targeting Windows and macOS systems.

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted Office documents, with an integrated hosting…

Proof-of-concept exploit for CVE-2020-12124 targeting Wavlink AC1200 router, demonstrating unauthenticated command injection and stack buffer…

CVE-2020-13159 - Artica Proxy before 4.30.000000 Community Edition allows OS command injection.

Ruby-based exploit for CVE-2023-34362 targeting MOVEit Transfer. Automates unauthenticated RCE, creates sysadmin accounts, and deploys a remote shell…

Python exploit for CVE-2014-6271 (ShellShock) enabling remote code execution via crafted environment variables in GNU Bash, targeting web servers and…

OpenPLC 3 WebServer Authenticated Remote Code Execution.

OpenPLC 3 WebServer Authenticated Remote Code Execution.

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

CVE-2023-51385

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office Word RCE) with a built-in HTTP server for payload delivery and…
