
commix
Automated All-in-One OS Command Injection Exploitation Tool

Automated All-in-One OS Command Injection Exploitation Tool

DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

CVE-2023-34468 Apache NiFi ExecuteSQL H2 RUNSCRIPT RCE PoC

Exploit for CVE-2026-9082, a Drupal JSON:API PostgreSQL SQL injection that escalates to RCE via preload library, with a local lab for testing.

Short Python script for exploiting CVE-2025–24000 based on this blog post: https://medium.com/@security_56355/from-subscriber-to-admin-reproducing-cve…

CVE-2025-53690 POC

A short and sweet simple exploit script for the CVE-2012-2982 Authenticated RCE vulnerability in the /file/show.cgi/bin endpoint.

A short scraper looking for a POC of CVE-2024-49112

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

kfd, short for kernel file descriptor, is a project to read and write kernel memory on Apple devices.

Proof-of-concept exploit for CVE-2023-24329, a Python urllib parsing flaw enabling URL confusion attacks. Includes a runnable script and references…

A writeup and theoretical Proof-of-Concept for CVE-2019-19194

general purpose workaround for the log4j CVE-2021-44228 vulnerability

On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code…

A short demo of CVE-2021-44228