
cve-2025-11953-vulnerability-demo
CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits…

CVE-2025-11953 demonstration: Critical RCE vulnerability in React Native CLI (CVSS 9.8). Educational security research with proof-of-concept exploits…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

Full-stack C2 framework for IoT exploitation (CVE-2020-25078) with real-time web panel, multi-source target acquisition, vulnerability scanning,…

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

Pre-Auth RCE in Sophos Web Appliance

PoC for CVE-2026-57588 - SQL injection in Nessus 10.12.0 XML import. Generates malicious .nessus files to enumerate databases, exfiltrate…

Go-based exploit for CVE-2022-40684 targeting Fortinet FortiGate devices. Automates authentication bypass to gain administrative access via the web…

Proof-of-concept demonstrating a command injection vulnerability in MS-Agent Shell tool, enabling arbitrary command execution and reverse shell via…

Exploit for CVE-2025-54123, an authenticated OS command injection in Hoverfly's middleware API, providing check-only, single-command, interactive…

Public security advisory for CVE-2025-66209, CVE-2025-66210, CVE-2025-66211, CVE-2025-66212, and CVE-2025-66213

Proof-of-concept demonstrating command injection in NETIS WF2409E router's ping and traceroute functions, allowing arbitrary command execution via…

CENG 325 - Principles of Information Security And Privacy

Proof-of-concept exploit for Samba usermap script remote command execution (CVE-2007-2447), with reverse shell capability for controlled lab testing…

Proof-of-concept exploit for CVE-2022-41080 (OWASSRF) enabling remote code execution through Microsoft Exchange Outlook Web Access, bypassing…

This is a exploit of CVE-2021-32305 a web vulnerability to command injection on search.php path, this exploit allows execute commands.

CVE-2025-55182 Interactive PoC - React Server Components RCE - Educational Security Research

Python exploit for CVE-2021-36260 command injection in Hikvision web servers. Supports safe/unsafe vulnerability verification, remote command…