
CVE-2025-49132
This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.

This repository contains a Proof of Concept (PoC) for CVE-2025-49132, a critical vulnerability in Pterodactyl Panel versions < 1.11.11.

This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious…

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

A CVSS 10.0-rated vulnerability in the parquet-avro Java module allows remote code execution via unsafe deserialization when parsing schemas. Tracked…

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

WordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerability

Automated ret2win exploit tool for CTF challenges. Finds stack offset, generates payloads, supports remote exploitation, and attaches GDB for…

Chamilo LMS Unauthenticated Big Upload File that allows remote code execution

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

Billing CTF Machine_CVE-2023-30258_Remote Code Execution

Created this exploit for the Hack The Box machine, Blurry.

Build a database of libc offsets to simplify exploitation

A tool to analyze the network flow during attack/defence Capture the Flag competitions

This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.

All Credit to MaherAzzouzi (https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit). This is a copy of the exploit for CTFs

Script to demonstrate the Grafana directory traversal exploit (CVE-2021-43798).