
CVE-2009-0182
CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

Step-by-step reproduction environment for CVE-2018-6905, a stored XSS vulnerability in TYPO3 install.php, with Docker setup and payload execution…

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

Syncord is a CLI-based file synchronization and storage tool that uses Discord as an encrypted file storage.

POC of DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

Proof-of-concept exploit for CVE-2025-66676 demonstrating arbitrary process termination via IOBit Unlocker kernel driver, with checksum bypass…

Proof-of-concept for CVE-2023-50164 (Apache Struts 2), originally by jakabakos and adapted for the HTB Strutted lab environment. For educational use…

Proof-of-concept exploit for CVE-2025-46157: Remote code execution via insecure file upload in Timetrax V1 Attendance module, with EfsPotato-based…

Proof-of-concept exploit for CVE-2017-1000117 (Git SSH command injection) that writes command output to a web-accessible file. Part of VulApps…

Proof-of-concept exploit for CVE-2024-10586 targeting WordPress Debug Tool plugin. Automates arbitrary file upload leading to remote code execution…

Proof-of-concept exploit for CVE-2025-8081, an arbitrary file read in Elementor WordPress plugin, allowing authenticated admins to read sensitive…

Writeup och POC för CVE-2008-2992

Python exploit for CVE-2020-29607 that bypasses file upload restrictions in Pluck CMS to upload a PHP webshell, enabling remote command execution on…

Python script that generates a malicious RAR file exploiting CVE-2023-38831 to execute a reverse shell payload, intended for educational and ethical…

InfectPE - Inject custom code into PE file [This project is not maintained anymore]

Modified code so that we don´t need to rely on CAB archives

Educational exploit for CVE-2022-2588, a Linux kernel race condition leading to privilege escalation. Includes Vagrant setup for a vulnerable machine…