
CVE-2026-48909-Joomla-SP-Exploit
CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Proof-of-concept exploit for CVE-2026-20262 path traversal in Cisco Catalyst SD-WAN Manager, enabling authenticated remote arbitrary file write via…

Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224

Proof-of-concept exploit for CVE-2025-14174, a use-after-free in Chrome's V8 engine. Includes JavaScript PoC and HTML embed for identifying the…

Proof-of-Concept exploit for CVE-2025-9074 - Unauthenticated Docker API exposure allowing arbitrary container creation and host filesystem access.

Example PoC for CVE-2025-24813 (Tomcat RCE)

this is not stable

This is a Python 3 version of this exploit. Hope it works!!!

Educational trojan simulator for cybersecurity training, simulating phishing attacks with social engineering, system reconnaissance, anti-sandbox…

XSS to RCE in RenderTune v1.1.4 exploit

Serverside Template Injection (SSTI) RCE - THM challenge "whiterose"

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

Proof-of-concept exploit for CVE-2025-49132, abusing a file inclusion vulnerability in Pterodactyl to achieve remote code execution via pearcmd.php.

Proof-of-concept exploit for Next.js CVE-2025-66478, demonstrating RCE via insecure deserialization and prototype pollution in Server Actions.…

This repository contains some python scripts implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic…

CVE-2025-8088 exploitation chain + Quasar C2 multi-stage payload delivery

CVE-2019-15107 Webmin Exploit in C

An exploit for CVE-2020-6418 implementing a SHELF Loader. Published as part of Tmp.0ut volume 2