
unicorn
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

Bash proof-of-concept exploit for CVE-2026-33017 in Langflow, triggering a reverse shell callback to a netcat listener.

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Proof-of-concept exploit for CVE-2026-55168 demonstrating authenticated arbitrary file write via symlink planting during backup restore in Runtipi.

A simple toolkit to validate, exploit & gain an interactive shell via the react2Shell Next.js RCE.

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

Python3 exploit for CVE-2025-24893, a remote code execution vulnerability in XWiki Platform. Automatically detects HTTPS/HTTP, constructs a Groovy…

A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).

A simple C-based vulnerability in Webmin versions 1.890 to 1.920

Exploit For SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)

PoC for CVE-2018-15133 (Laravel unserialize vulnerability)

CVE-2021-3060

A simple application that shows how to exploit the CVE-2022-42889 vulnerability

A simple dockerize application that shows how to exploit the CVE-2022-42889 vulnerability.

Presents how to exploit CVE-2021-44228 vulnerability.

Proof-of-concept script that demonstrates bypassing macOS Gatekeeper, notarization, and XProtect checks by exploiting CVE-2021-30853, allowing…

log4j2 Log4Shell CVE-2021-44228 proof of concept

CVE-2018-12386 - Firefox Sandboxed RCE Exploit for Linux (Firefox <v62.0.3)