
CVE-2020-25042-PoC
PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

Automated exploit toolkit for CVE-2026-1555, a critical unauthenticated file upload RCE in the WebStack WordPress theme. Features PyQt5 GUI,…

CVE-2026-44789 — n8n <1.123.43 HTTP Request pagination prototype pollution to RCE (NODE_OPTIONS runner-spawn gadget). Lab + automated PoC, verified…

Python-based exploit module targeting CVE-2026-10520 with automated payload delivery and vulnerability verification for penetration testing…

Automated Metasploit post-exploitation module for CVE-2026-31431 ("Copy Fail"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG…

CVE-2026-33017 exploitation tool for Langflow <1.9.0. Features reverse shells, command execution, file operations, persistence, and automated…

Proof-of-concept exploit for CVE-2025-54322, a critical pre-authentication RCE in XSpeeder SXZOS firmware. Provides interactive shell, reverse shell…

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

PoC exploit for Fastjson RCE (CVE-2026-16723) featuring automated JAR payload generation and delivery via crafted JSON, bypassing AutoType…

Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell…

Proof-of-concept exploit for CVE-2019-11043, a PHP-FPM underflow vulnerability, built on the pocsuite framework for automated web application…

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

🔥 Automated RCE Exploit for Limesurvey (CVE-2021-44967). Cadena de explotación optimizada para escalada de privilegios. 🚀

Exploit tool targeting CVE-2026-43499 with automated payload delivery and vulnerability verification for penetration testing engagements.

Dockerized proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components via prototype pollution, with automated exploit scripts and…

Metasploit module for exploiting CVE-2022-30526, providing automated remote code execution against vulnerable targets.