
CVE-2025-66478-Exploit-Poc
Proof-of-concept exploit for Next.js CVE-2025-66478, demonstrating RCE via insecure deserialization and prototype pollution in Server Actions.…

Proof-of-concept exploit for Next.js CVE-2025-66478, demonstrating RCE via insecure deserialization and prototype pollution in Server Actions.…

Python 3 exploit for Kibana < 6.6.1 RCE (CVE-2019-7609) via prototype pollution, with automatic version detection and optional reverse shell.

JavaScript-based exploit for Chrome V8 vulnerability CVE-2020-6468, with a d8 shell script and an HTML-based Chrome target.

Proof-of-concept exploit for critical RCE (CVSS 10.0) in Next.js/React Server Components via deserialization manipulation. Includes Python script for…

Reproducible environment and PoC for CVE-2024-53900, a critical RCE in Mongoose via populate().match $where. Includes automated exploit script and…

Proof-of-concept exploit for CVE-2025-24801, an LFI-to-RCE vulnerability in GLPI 10.0.17. Automates login, enables PHP uploads, and uploads a reverse…

Python-based exploit for CVE-2024-25600 targeting Bricks Builder WordPress plugin RCE. Automates nonce extraction, payload injection, and arbitrary…

Improved exploit script for CVE-2025-55182 React Server Components RCE vulnerability with manual multipart construction for reliable detection and…

Proof-of-concept script demonstrating unauthenticated remote code execution in Sourcecodester Poultry Farm Management System via the vulnerable…

Python proof-of-concept for CVE-2026-3844, an unauthenticated arbitrary file upload in WordPress Breeze Cache plugin, enabling remote code execution.…

A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.

Proof-of-concept exploit for CVE-2025-55182 (React2Shell), a critical RCE vulnerability in React Server Components via unsafe deserialization.…

Automated JBoss exploitation script deploying JSP shells with bind/reverse shell, Meterpreter, and VNC support for penetration testing.

Docker-based environment to reproduce CVE-2020-7247 (OpenSMTPD) with a Python exploit script for arbitrary command execution and reverse shell via…

Reproducible Proof-of-Concept for CVE-2021-3007 (Laminas/Zend HTTP deserialization RCE) with a standalone exploit script, Nuclei template, and…

Post-authentication remote code execution exploit for Microsoft Exchange Server (CVE-2022-41082) with a PowerShell privilege escalation script for…

CVE-2022-39197 RCE POC

Arbitrary Code Execution on FuguHub 8.4