
CVE-2026-3844
Python proof-of-concept for CVE-2026-3844, an unauthenticated arbitrary file upload in WordPress Breeze Cache plugin, enabling remote code execution.…

Python proof-of-concept for CVE-2026-3844, an unauthenticated arbitrary file upload in WordPress Breeze Cache plugin, enabling remote code execution.…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

This simple but powerful script will introduce a new type of malware that will turn off the firewall, start an HTTP server, forward its port through…

A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.

Demonstrating Remote Code Execution Vulnerability via Pickle Serialization in ClearML

Shellcodes for Windows >= 11 x64

Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713

MindsDB Path Traversal to RCE PoC

Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)

PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)

Proof-of-concept exploit for critical RCE (CVSS 10.0) in Next.js/React Server Components via deserialization manipulation. Includes Python script for…

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

Proof-of-concept exploit for CVE-2024-6387 (regreSSHion) targeting unauthenticated remote code execution in OpenSSH server via signal handler race…

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

Proof-of-Concept exploit for Apache Struts S2-052 (CVE-2017-9805) XML Deserialization Remote Code Execution. Created while solving the INE eWPTX…

This is a POC script for CVE-2025-55182 (React SSR RCE)

Proof-of-concept exploit for CVE-2025-55182, a critical RCE vulnerability in Next.js Server Actions. Exploits insecure deserialization in the React…