
CVE-2026-33017
Bash proof-of-concept exploit for CVE-2026-33017 in Langflow, triggering a reverse shell callback to a netcat listener.

Bash proof-of-concept exploit for CVE-2026-33017 in Langflow, triggering a reverse shell callback to a netcat listener.

Proof-of-concept for Git LFS pointer poisoning, with Bash and Python scripts that create a malicious repository, simulate a rogue LFS server, and…

A bash script for easyly exploiting ImageMagick Arbitrary File Read Vulnerability CVE-2022-44268

A bash scanner for detecting CVE-2025-55182 vulnerability in Next.js applications. And a PoC nodejs script

CVE-2023-34468 Apache NiFi ExecuteSQL H2 RUNSCRIPT RCE PoC

I write the python and bash Proof of Concept for the better understanding of attacks.

Python proof-of-concept exploit for CVE-2026-41651, a TOCTOU local privilege escalation in PackageKit allowing unprivileged users to install packages…

Provides a bash workaround script to mitigate CVE-2026-31431, preventing remote code execution via copy.fail exploit. Includes usage instructions for…

CVE-2010-2075 exploit

Writeup och POC för CVE-2008-2992

Full-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification,…

Proof of Concept for CVE-2026-1281 & CVE-2026-1340 - Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion

Bash exploit for CVE-2025-24893, unauthenticated RCE in XWiki Platform, using template injection in the SolrSearch macro to execute arbitrary system…

CVE-2023-46818 - ISPConfig PHP Code Injection PoC Exploit (Bash)

Python exploit for CVE-2014-6271 (Shellshock) targeting vulnerable CGI scripts with reverse shell handler, supporting HTTP/HTTPS, custom paths, and…

Python exploit for CVE-2023-26326 (WordPress BuddyForms) chained with CVE-2024-2961 to achieve unauthenticated remote code execution via php://filter…

CVE-2024-32002 是 Git 中的一个严重漏洞,允许攻击者在用户执行 git clone 操作时远程执行任意代码(RCE)。

Personally crafted Bash Bunny Payloads