
CVE-2026-29053
Python PoC and version scanner for CVE-2026-29053, an authenticated RCE in Ghost CMS below 6.19.1 via malicious Handlebars theme templates.

Python PoC and version scanner for CVE-2026-29053, an authenticated RCE in Ghost CMS below 6.19.1 via malicious Handlebars theme templates.

Proof-of-concept for CVE-2026-33017, demonstrating unauthenticated remote code execution in vulnerable Langflow versions through malicious…

Python PoC exploit for CVE-2025-59528, achieving authenticated RCE on Flowise AI <= 3.0.4 via the customMCP endpoint and Node.js…

Proof-of-concept exploit for CVE-2024-25641, an authenticated RCE in Cacti 1.2.26 via the Package Import feature, enabling arbitrary PHP code…

First open source and publicly available System Management Mode backdoor for UEFI based platforms. Good as general purpose playground for various SMM…

Python codes of my blog.

ipfire 2.25 authenticated remote code execution

Patch PE, ELF, Mach-O binaries with shellcode new version in development, available only to sponsors

Buffer Overflow Vulnerability that can result ACE

Proof-of-concept exploit for CVE-2024-54160 demonstrating stored XSS and HTML injection in OpenSearch Reports plugin via malicious iframe payload in…

Log4j Vulnerability RCE - CVE-2021-44228

This is the PoC exploit for CVE-2022-41840, running Zenario

(PoC) Python version of CVE-2019-11043 exploit by neex

TP Seguridad Informática UTN FRBA 2021

Python port of a Metasploit exploit targeting CVE-2004-1561 for remote code execution. Designed for penetration testing and vulnerability validation…

This is a Python 3 version of this exploit. Hope it works!!!

A critical RCE vulnerability has been identified in the Wazuh server due to unsafe deserialization in the wazuh-manager package. This bug affects…

Python exploit PoC for CVE-2022-23935 targeting exiftool 12.37, enabling remote code execution via crafted image files.