
CVE-2026-42945
A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending…

A flaw was found in NGINX, specifically within the ngx_http_rewrite_module. An unauthenticated attacker can exploit this vulnerability by sending…

Proof-of-concept exploit for a command injection vulnerability in Syrotech SY-GOPON-8OLT-L3, allowing arbitrary command execution via HTTP request…

Python exploit script targeting Cacti CVE-2020-8813 for unauthenticated remote code execution via crafted HTTP requests.

Python exploit for CVE-2014-6271 (Shellshock) that targets a vulnerable CGI endpoint via HTTP and executes arbitrary system commands.

Exploit script for CVE-2022-24816 targeting GeoServer. Executes arbitrary commands on vulnerable servers via crafted HTTP requests. Includes…

Automated exploitation tool for CVE-2019-0232 (Apache Tomcat CGI RCE) with command execution and reverse shell modes, automatic URL encoding, and…

Go-based exploit for CVE-2014-6271 (Shellshock) that sends crafted HTTP requests to execute arbitrary commands on vulnerable servers.

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

Remote Command Execution exploit for Rejetto HTTP File Server 2.3.x (CVE-2014-6287) rewritten in Python 3 for modern offensive security testing.

CVE-2024-39943 rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated…

Proof-of-concept exploit for CVE-2024-3400, a command injection vulnerability in Palo Alto firewalls, demonstrating file creation and remote command…

Rejetto http File Server 2.3.x (Reverse shell)

Shellshock (CVE-2014-6271) exploit script for remote command execution against vulnerable CGI endpoints via HTTP headers.

Exploit for CVE-2022-46169 in Cacti, enabling unauthenticated remote code execution via crafted HTTP requests to remote_agent.php.

Proof-of-concept exploit for CVE-2020-14882 in Oracle WebLogic Server, demonstrating remote code execution via crafted HTTP requests to the console…

Python-based exploit for CVE-2014-6287 in HTTP File Server 2.3.x, delivering a reverse shell via Base64-encoded PowerShell payload for authorized…

Go-based scanner and exploit for CVE-2020-5902, targeting F5 BIG-IP devices. Supports command execution and file reading via HTTP requests, enabling…

Generates malicious DOCX documents exploiting CVE-2021-40444 (Microsoft Office Word RCE) with a built-in HTTP server for payload delivery and…