
CVE-2024-56278
Proof-of-concept exploit for CVE-2024-56278, a remote code execution vulnerability in the WP Ultimate Exporter WordPress plugin, demonstrating file…

Proof-of-concept exploit for CVE-2024-56278, a remote code execution vulnerability in the WP Ultimate Exporter WordPress plugin, demonstrating file…

Proof-of-concept exploit for Ghost CMS remote code execution via prototype pollution in jsonpath and static-eval, with a vulnerable environment setup…

Proof-of-concept exploit for CVE-2023-5966, an arbitrary file upload vulnerability in EspoCRM 2.7.4 and earlier, enabling remote code execution via a…

Rust-based local privilege escalation exploit for CVE-2026-31431, enabling execution of custom shellcode such as Meterpreter on Linux systems.

Rust implementation of the CVE-2021-4034 pkexec privilege escalation exploit, with scripts to download and unpack a vulnerable pkexec for testing.

Impacket-based exploit for CVE-2021-1675/34527 (PrintNightmare) enabling remote or local DLL execution on vulnerable Windows systems, with scanning…

Proof of Concept for CVE-2021-4034 (with experimental traceless exploitation)

Local privilege escalation exploit for CVE-2021-1675 (PrintNightmare) that installs a malicious DLL to gain SYSTEM access on vulnerable Windows…

Exploit for CVE-2023-48022, adapted from Bishop Fox research. Configure IP, port, and payload to execute against vulnerable Ray instances.

Exploit for CVE-2025-55182 enabling remote code execution via prototype pollution in Next.js React Server Components, with command execution and…

CVE-2026-31816 - Budibase Authentication Bypass to RCE

PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

UAC bypass for x64 Windows 7 - 11

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

Simulated macOS/iOS XPC service vulnerable to NSKeyedUnarchiver deserialization, plus exploit demonstration and crafted plist payload for RCE via…