
CVE-2025-48384-poc
PoC for CVE-2025-48384

PoC for CVE-2025-48384
gethostbyname*() buffer overflow exploit in glibc - CVE-2015-0235 https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vuln…

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection payloads, WAF bypass techniques, and passive scanning integration for…

A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells,…

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.

STACK BUFFER OVERFLOW EXPLOIT RESULTING IN REMOTE CODE EXECUTION

CVE-2025-60021

CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and…

From Information Disclosure to RCE in Sitecore Experience Platform (XP)

Proof-of-concept exploit for CVE-2026-33937, a Handlebars AST injection vulnerability leading to remote code execution in Node.js. Demonstrates…

CVE-2023-4220 PoC Chamilo RCE

Proof-of-concept exploit for CVE-2023-32571 demonstrating Dynamic Linq injection to achieve remote code execution, with a Docker-based lab…

Fixed proof-of-concept exploit for CVE-2024-9264, a critical Grafana RCE via DuckDB SQL expressions. Executes reverse shell using corrected shellfs…

Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components

Proof-of-concept exploit for CVE-2024-22515, demonstrating arbitrary file upload and remote code execution in Agent DVR 5.1.6.0 via unverified sound…

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

POC for CVE-2025-24813 using Spring-Boot

Proof-of-concept demonstrating CVE-2024-32002 remote code execution via malicious Git submodule hook, targeting Windows and macOS systems.