
wp2shell-poc
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of…


CVE-2021-27928 MariaDB/MySQL-'wsrep provider' 命令注入漏洞

Python script for exploiting command injection in Open PLC Webserver v3

BLE-based C2 server for Hak5 Bash Bunny enabling wireless command injection, payload delivery, and remote control over Bluetooth Low Energy.


Evince/xreader/Atril RCE exploit to CVE-2026-46529

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

Remote OS Command Injection in TastyIgniter v3.0.7 Sendmail Path field

CVE-2025-57819 -> rce

CVE-2025-54123 Hoverfly Authenticated Middleware Command Injection RCE

Remote authentication bypass exploit for GNU inetutils-telnetd (CVE-2026-24061) using CRLF injection to gain instant root shell. Supports single/mass…

[CVE-2021-22123] Fortinet FortiWeb Authenticated OS Command Injection

osCommerce Phoenix CE <=1.0.5.4 Authenticated RCE

CyberPanel authenticated RCE < 2.3.8

pdf_info <= 0.5.3 OS Command Injection

Python RCE exploit for Sendmail with ClamAV-Milter <0.91.2 (CVE-2007-4560). Remote root command injection via SMTP RCPT TO headers.