
craftcms-cve-2025-32432-rce
Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research

Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.

Apache Flink Dashboard未授权访问-远程代码命令执行

Exploits CVE-2026-64638 to convert cross-site scripting into shell access on vulnerable web applications, automating payload delivery and…

Jenkins Git Client RCE CVE-2019-10392_Exp


This is Metasploit module who exploit the command injection vulnerability in control center of the agent Tesla.

Authenticated Remote Command Execution – pfSense <= 2.1.3

Python exploit for CVE-2025-70559 targeting an upload directory bypass/remote code execution; run with LHOST and LPORT to establish a reverse shell.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A Test API for testing the POC against CVE-2022-1388

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP…

Testing

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

Proof-of-concept HTML page that reproduces CVE-2019-10070, a cross-site scripting vulnerability in Apache Atlas, for validation and defensive testing.

Intercept, modify, repeat and attack Android's Binder transactions using Burp Suite

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB