
watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
CVE-2026-8452 PreAuth RCE

CVE-2026-8452 PreAuth RCE

A repository that contains all the working PoC I have crafted for known CVEs, and details on any ongoing research I am currently doing (mostly Iot…

Exploit code for CVE-2026-50657 targeting Nese Vista through Nese 11 (BETA). Includes patch details and affected OS versions for security testing and…

Repo contains the PoC and steps to reproduce cve 2023-38646

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

DCOM in memory and fileless lateral movement techniques through .Net deserilization

Proof-of-concept demonstrating SQL injection and unrestricted file upload chained to achieve remote code execution in Visitor Management System 1.0,…

CVE-2025-49113 – Roundcube ≤1.6.10 post-auth RCE via PHP object deserialization (HackTheBox CTF)

Proof-of-concept exploit for CVE-2025-69212: OS command injection in OpenSTAManager's P7M file processing, enabling authenticated remote code…

Proof-of-concept exploit for CVE-2026-33229, an XWiki RCE via Apache Velocity sandbox bypass, with technical details and a working payload.

Step-by-step guide to exploit a buffer overflow in FreeFloat FTP Server using Python fuzzing, Immunity Debugger with mona.py, and IDA Free for binary…

Python PoC for CVE-2025-60787, authenticated OS command injection RCE in motionEye <= 0.43.1b4 via unsanitized image_file_name config

Proof of concept demonstrating command execution in Microsoft Notepad via crafted files, enabling arbitrary code execution and system compromise.

Proof-of-concept exploit for CVE-2024-0692 targeting SolarWinds SEM, developed from penetration testing research to demonstrate remote code execution.

CVE-2025-33073

CVE-2025-48593

CVE-2019-3396 confluence SSTI RCE

CVE-2023-30990 exploits