
CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE
Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

Python exploit for CVE-2024-55591, bypassing FortiOS authentication to execute remote commands on vulnerable FortiGate and FortiProxy devices.

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

AV/EDR processes termination by exploiting a vulnerable driver (BYOVD)

Unauthenticated remote code execution exploit for Oracle WebLogic CVE-2017-10271. Provides XML payload and endpoint list for penetration testing of…

Proof-of-concept exploit for CVE-2020-11651 and CVE-2020-11652 enabling remote command execution and filesystem access on vulnerable SaltStack…

Exploit script for CVE-2025-55182 that deploys a Godzilla memory shell on vulnerable web servers, with support for proxy and encoding options.

Exploit for CVE-2023-33246 in Apache RocketMQ. Modifies configuration properties to execute arbitrary commands on vulnerable servers, enabling remote…

Proof of conept to exploit vulnerable proxycommand configurations on ssh clients (CVE-2023-51385)

Proof-of-concept exploit for CVE-2022-35914, a command injection vulnerability in GLPI via a third-party library script. Executes arbitrary commands…

Tool to check if an IP of a DblTek GoIP is vulnerable to a challenge-response login system, send SMS messages from the system, execute remote…

Authenticated remote code execution exploit for Webmin (CVE-2019-15642). Provides a Python script to execute arbitrary commands on vulnerable Webmin…

Proof-of-concept exploit for CVE-2023-34992 enabling unauthenticated blind command injection as root on vulnerable Fortinet FortiSIEM appliances.

pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.…

Proof-of-concept exploit for CVE-2024-8190, an authenticated command injection vulnerability in Ivanti Cloud Service Appliance, enabling remote…

PoC exploit for CVE-2023-6019 targeting unauthenticated Remote Code Execution in Anyscale Ray Dashboard via the Jobs API. Delivers a reverse shell on…