
CVE-2024-29973
Exploiter a Vulnerability detection and Exploitation tool for CVE-2024-29973 with Asychronous Performance.

Exploiter a Vulnerability detection and Exploitation tool for CVE-2024-29973 with Asychronous Performance.

Python exploit and detection script for CVE-2024-27348, a remote code execution vulnerability in Apache HugeGraph Server via the Gremlin traversal…

Go-based exploit for CVE-2022-22947, a SpEL injection vulnerability in Spring Cloud Gateway, enabling remote command execution via the Actuator API.

Demonstration of Windows MSDT Vulnerability (CVE-2022-30190)

Automated browser crash tool exploiting CVE-2020-27950 (iOS WebKit) via Metasploit and ngrok. Generates public malicious URL for controlled…

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Reproduction of cve-2024-3400-panos_rce_reproduction

Proof-of-concept demonstrating OS command injection in Warp's legacy SSH background command handling (CVE-2026-48732). Includes local simulation of…

Authenticated remote code execution exploit for Webmin < 1.997 via the Software Package Updates module. Injects arbitrary commands as root through an…

This is a Chained RCE in the Havoc C2 framework using github.com/chebuya and github.com/IncludeSecurity pocs

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

Technical advisory and proof-of-concept for CVE-2024-13985, a critical unauthenticated remote code execution vulnerability in Dahua EIMS via command…

A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter.

This project provides a fully functional demonstration of CVE-2025-55182 (React2Shell) - a critical Remote Code Execution vulnerability in React…

Command injection vulnerability in elFinder <= 2.1.47 via the PHP connector component. Allows unauthenticated remote code execution as the web server…

A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4

Proof of Concept for CVE-2025-24893 demonstrating unauthenticated remote command execution in XWiki through unsafe server-side template evaluation.