
CVE-2026-54121-PoC-Exploit
👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

Exploit chain for unauthenticated RCE on Microsoft SharePoint, combining a JWT authentication bypass with unsafe .NET type instantiation to achieve…

CVE-2026-39154, Stored XSS in CometChat JS SDK

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

Automated exploit for CVE-2025-69212 command injection in OpenSTAManager, featuring admin authentication, malicious ZIP upload, and reverse shell or…

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

CVE-2026-31816 - Budibase Authentication Bypass to RCE

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

Kestra Unauthenticated RCE Exploit (CVE-2026-53576)

CVE-2021-26855: PoC (Not a HoneyPoC for once!)

Unauthenticated administrator takeover exploit for CVE-2026-66012 using MCP missing authorization to exfiltrate credentials and achieve remote code…

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction

CVE Reproduction: cve-2024-0012_9474-panos_authbypass_reproduction

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1).

CVE-2026-63030 / wp2shell