
CVE-2025-59287-Exercise-Use
Purple team exercise scripts demonstrating CVE-2025-59287, an unauthenticated RCE in WSUS via malicious deserialization payload injection into the…

Purple team exercise scripts demonstrating CVE-2025-59287, an unauthenticated RCE in WSUS via malicious deserialization payload injection into the…

This is the PoC exploit for CVE-2022-41840, running Zenario

Python 3 exploit for Kibana < 6.6.1 RCE (CVE-2019-7609) via prototype pollution, with automatic version detection and optional reverse shell.

Educational repository for learning CVE-2025-55182: a pre-authentication RCE in React Server Components. Includes step-by-step documentation,…

A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells,…

Proof-of-concept exploit for CVE-2025-32433, a pre-authentication RCE in Erlang/OTP SSH daemon. Includes Python script to send crafted SSH channel…

CVE-2023-4220 PoC Chamilo RCE

Fixed proof-of-concept exploit for CVE-2024-9264, a critical Grafana RCE via DuckDB SQL expressions. Executes reverse shell using corrected shellfs…

CVE-2025-60021

Authenticated RCE PoC for Cacti (CVE‑2025‑24367). Uses graph template injection to write and execute a payload via the “Unix – Logged in Users”…

CVE-2025-47812

CVE-2021-44228 vulnerability study

Reproducible environment and PoC for CVE-2024-53900, a critical RCE in Mongoose via populate().match $where. Includes automated exploit script and…

Penetration testing utility and antivirus assessment tool.

Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002

Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This…