
CVE-2025-31161
Go-based exploit for CVE-2025-31161 targeting crushFTP, enabling remote admin account creation via crafted HTTP requests.

Go-based exploit for CVE-2025-31161 targeting crushFTP, enabling remote admin account creation via crafted HTTP requests.

Proof-of-concept exploit for CVE-2025-26153: stored XSS in Chamilo LMS forum threads enabling privilege escalation from regular user to admin via…

Exploit for CVE-2018-14324 achieving RCE on Eclipse GlassFish 5 via JMX MLet MBean with hardcoded admin credentials, using Beanshooter for stager…

PowerShell exploit for PrintNightmare (CVE-2021-1675) performing local privilege escalation via Print Spooler, with custom DLL payload injection to…

Proof-of-concept exploit for CVE-2024-27956, a SQL injection in ValvePress Automatic WordPress plugin. Creates admin user and enables remote code…

Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

Exploit for Rocket.Chat 3.12.1 NoSQL Injection to RCE (CVE-2021-22911). Automates unauthenticated exploitation with low-privilege user password to…

Crafthemes Demo Import <= 3.3 - Authenticated ( Admin+) Arbitrary File Upload in process_uploaded_files

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

Obfuscates PE binaries into fileless loaders that add PE sections, unhook ntdll, and exploit signed drivers to remove kernel callbacks for EDR…

BOF to impersonate TrustedInstaller via DISM API trigger and thread impersonation

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

Proof-of-concept exploit for CVE-2024-4040 (CrushFTP) providing unauthenticated file read, credential decryption, and remote code execution via…

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Authenticated RCE exploit for Grav CMS via plugin upload, demonstrating arbitrary PHP code execution and reverse shell.

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…