
CVE-2026-87902
Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE…

Exploit for CVE-2025-64512 to get a reverse shell.

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

Heap OOB write in MariaDB JSON_SCHEMA_VALID() → persistent privilege escalation (lab-assisted)

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

A collection of selenium tests that might aid it takeover of a selenium node

Chaining Havoc C2 SSRF with RCE to get reverse shell on Havoc C2 Server.

CVE-2025-24893 is a critical unauthenticated remote code execution (RCE) vulnerability in XWiki, a popular open-source enterprise wiki platform.

Get your data from the resource section manually, with no need for windows apis

Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.

CVE-2023–4220 Exploit

Authenticated remote code execution exploit for WordPress WP All Import plugin <= 3.6.7 (CVE-2022-1565). Uploads arbitrary files via insecure file…

Proof Of Concept for the CVE-2016-10033 (PHPMailer)

Exploit for Ivanti Automation Manager CVE-2022-44569

LSTAR - CobaltStrike Translated to EN

Python codes of my blog.