
cve-2026-0013-exploit
Proof-of-concept exploit for CVE-2026-0013, demonstrating a remote code execution vulnerability in a target application. Includes payload generation…

Proof-of-concept exploit for CVE-2026-0013, demonstrating a remote code execution vulnerability in a target application. Includes payload generation…

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

Proof-of-concept exploit for CVE-2023-38408, demonstrating exploitation of a remote code execution vulnerability in a targeted application or service.

CVE-2022-29359 - School Application System Stored Cross-Site Scripting

Demonstrates Log4Shell (CVE-2021-44228) exploitation with LDAP server, malicious JNDI payload, and vulnerable Spring Boot application for security…

Proof-of-concept exploit for arbitrary code execution through eval() injection in a ham radio programming application, including malicious .itm/.img…

A Proof-of-Concept demonstrating the application of 3D Navier-Stokes CTT formulations to packet flow optimization and defensive bypass.

A VBA implementation of the RunPE technique or how to bypass application whitelisting.

Python script to inject existing Android applications with a Meterpreter payload.

PoC for CVE-2018-15133 (Laravel unserialize vulnerability)

RCE exploit for dompdf

That repository contains my updates to the well know java deserialization exploitation tool ysoserial.

I'll submit the poc after blackhat

Exploit Java deserialization vulnerabilities in WebLogic, WebSphere, JBoss, Jenkins, and OpenNMS using Python PoC scripts and crafted HTTP requests.

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

CVE-2022-41852 Proof of Concept (unofficial)

PoC for CVE-2016-1000027

[CVE-2019-18935] Telerik UI for ASP.NET AJAX (RadAsyncUpload Handler) .NET JSON Deserialization