
JavaPayload
Pure Java payload collection for post-exploitation, triggered by Java exploits or misconfigured services like unprotected Tomcat Manager consoles and…

Pure Java payload collection for post-exploitation, triggered by Java exploits or misconfigured services like unprotected Tomcat Manager consoles and…

DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

PoC exploit for CVE-2024-55963 targeting unauthenticated remote code execution on Appsmith Enterprise via misconfigured PostgreSQL. Supports…

Demonstrates a Python object injection and arbitrary code execution exploit in Linux Mint's software manager (CVE-2019-17080) via unsafe pickle…

Local privilege escalation exploit for Trend Micro OfficeScan Client <=10.0 via misconfigured ACLs on the installation folder, enabling system-level…

Simple Dashboard <= 2.0 - Unauthenticated Privilege Escalation

nameko Arbitrary code execution due to YAML deserialization

Proof-of-concept exploit for CVE-2024-25293 demonstrating remote code execution in mjml-app via crafted mj-button href attributes, with a Python…