
CHIRP-CodeExecution_via_Malicious_ImageFile
Proof-of-concept exploit for arbitrary code execution through eval() injection in a ham radio programming application, including malicious .itm/.img…

Proof-of-concept exploit for arbitrary code execution through eval() injection in a ham radio programming application, including malicious .itm/.img…

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

Proof-of-concept for CVE-2019-11932, a double-free vulnerability in WhatsApp's MP4 parser, demonstrating memory corruption through a crafted media…

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

The above investigation of the ES file browser security weakness allows us to see the issue in its entirety

Proof-of-concept exploit for CVE-2024-22514 enabling remote code execution in iSpyConnect Agent DVR 5.1.6.0 via malicious objects.xml file…

A vulnerability scanner that detects CVE-2021-21980 vulnerabilities.

Exploits CVE-2024-51793 unauthenticated arbitrary file upload in WordPress Computer Repair Shop plugin, scans target lists, uploads PHP webshells,…

Proof-of-concept exploit for CVE-2024-22515, demonstrating arbitrary file upload and remote code execution in Agent DVR 5.1.6.0 via unverified sound…

Proof-of-concept checker for CVE-2025-10951, an unauthenticated path traversal in ml-logger, validating arbitrary file read via /glob and /stream…

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

Proof-of-concept exploit for CVE-2022-31793 with IP/file-based target scanning, validation mode, and arbitrary file read via HTTP requests.

Proof-of-concept exploit for CVE-2026-37748, an unrestricted file upload vulnerability in Visitor Management System 1.0 leading to remote code…

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…

Shell-based exploit for CVE-2021-41773 targeting Apache HTTP Server path traversal vulnerability, enabling unauthenticated remote file disclosure and…

CVE-2024-0044: a "run-as any app" high-severity vulnerability affecting Android versions 12 and 13