
CVE-2018-7600-Drupalgeddon2-RCE
Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for…

Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for…

CVE-2019-13132 — libzmq CURVE INITIATE stack overflow → RCE. Working exploit + Docker lab.

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Proof-of-concept exploit for CVE-2026-54806: unauthenticated PHP object injection in WP Activity Log plugin enabling blind RCE via User-Agent header.…

Scanner and exploit toolkit for CVE-2025-55182, a critical pre-auth RCE in React Server Components. Includes detection, interactive shell, Docker…

PoC exploit for an unauthenticated RCE in Langflow <=1.8.1, including source-level root cause analysis, AST-aware reverse shell payload, Docker lab,…

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

Proof of Concept for CVE-2025-55182 ("React2Shell"). A fully dockerized environment demonstrating Remote Code Execution (RCE) via insecure…

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), demonstrating remote code execution in React Server Components through crafted Next-Action…

Java-based exploit for CVE-2024-20931 bypassing CVE-2023-21839 patch in Oracle WebLogic. Uses JNDI injection via ForeignOpaqueReference to achieve…

Proof-of-concept exploit for CVE-2026-6471, demonstrating privilege escalation in PostgreSQL via logical decoding dlopen to achieve arbitrary code…

I know you are probably here from Hack the Box, if so, yes this one actually works.

Python exploit for CVE-2019-11043 targeting PHP-FPM buffer underflow to achieve remote code execution via null byte overwrite and FastCGI variable…

Proof-of-concept exploit for CVE-2022-1329, a remote code execution vulnerability in WordPress Elementor 3.6.0-3.6.2. Includes Docker-based…

Proof-of-concept exploit for CVE-2024-45590, demonstrating unauthenticated remote code execution in a WordPress plugin via arbitrary file upload.…

Exploit Development for CVE-2023-6553 on Backup Plugin in Wordpress

CVE-2022-42889 aka Text4Shell research & PoC